CSR Parser & Signature Checker

Parse a PEM/DER CSR, show subject, public key and DNS/IP SANs, and verify its embedded signature locally.

Privacy: all processing happens locally in your browser. Your input never leaves your device.

What is CSR Parser & Signature Checker?

A CSR signature proves possession of its corresponding private key; it is not a certificate issued by a CA. This tool reads a PKCS#10 CSR's subject, public key, requested SANs and extensions, then verifies that its self-signature matches the public key. A valid result means the encoded request was not altered in a way that breaks its signature. It does not prove domain control, organizational identity or that a CA will issue a certificate.

How to Use

  1. Paste or import a PEM/DER CSR
  2. Review the subject, public key, DNS/IP SANs and requested extensions
  3. Check the signature result before sending the request into a CA workflow

FAQ

Does a valid CSR signature prove I own the domain?
No. It proves possession of the private key only; a CA still performs domain-control validation.
Why are DNS and IP SANs separate?
They are distinct name types. An IP address must be encoded as an IP SAN, not as DNS text, for client matching to work.
Can I compare a CSR with my private key?
Yes. Compare the CSR public key against the public key extracted from your private key; do not attach the private key to the CSR.

Related Tools

Last updated 2026-10-09