Skip to main content

Common problems

Why is a domain I do not own on my certificate?

Usually because a shared hosting platform bundled you onto one certificate with other customers. Here is when that is normal and when it is worth a question.

On this page

You looked at your certificate and there are names on it belonging to companies you have never heard of.

This is almost always mundane. Certificates can list many names in their subject alternative name field, and shared hosting platforms, CDNs, and website builders routinely put dozens of customers on a single certificate rather than issuing one each. Your site and a stranger’s site are served by the same infrastructure, so they share the certificate that infrastructure presents.

When it is expected

SituationWhy it happens
Shared hosting or a website builderOne certificate covers many customer domains on the same edge
A CDN on a shared planThe edge presents a bundled certificate unless you pay for a dedicated one
A SaaS product with custom domainsYour subdomain rides along with other tenants’ custom domains
A platform’s default certificateYou are hitting a fallback certificate rather than one configured for your name

If you are on a managed platform and never handled a private key yourself, this is the expected arrangement and not a finding.

When it deserves a question

Worth following up if any of these apply:

  • You run your own infrastructure and issue your own certificates. Nobody else should be on them.
  • The other names look like a former parent company, an old brand, or an agency you no longer work with. That points at a deployment nobody has revisited.
  • You are on a plan you believed included a dedicated certificate.
  • The names appear on an endpoint you did not know existed.

In each case the question is the same and it is a short one: who controls this certificate and its private key, and is that still the arrangement you intended?

What being listed does and does not mean

Being named on a certificate does not give the other party access to anything of yours. There is no capability attached to appearing in a SAN list.

What matters is the private key, and on a shared certificate that key belongs to the platform operator. They can already terminate TLS for your domain, which is inherent to using them. The other customers on the list cannot.

It also does not establish common ownership in the other direction. Two names on one certificate means one operator, not one company.

Reduce the surprise next time

A CAA record restricts which certificate authorities may issue for your domain at all, which limits how a certificate you did not expect can come into existence. It is a few DNS records and it is the most direct control you have here. See CAA certificate issuance policies, and check the renewal path before narrowing it.

If you want a dedicated certificate, most platforms offer one, often on a higher tier.

For how these relationships appear in a report and why the scope stays with the domain you submitted, see adjacent domains and certificate relationships.

Questions people ask

Is it dangerous to share a certificate with other domains?

On a managed platform it is normal and the private key stays with the provider. It is worth attention when you did not expect it, because it means whoever controls that certificate controls the key that authenticates your site.

Can the other domain on my certificate read my traffic?

Not by virtue of being listed. Being named on a certificate does not grant access to anything. What matters is who holds the private key, which is the platform operator, not the other customers.

How do I get my own certificate instead?

Most platforms offer a dedicated or custom certificate option, sometimes on a higher tier. If you need control over issuance, a certificate you obtain and deploy yourself is the answer, along with a CAA record restricting who may issue for your domain.

Last verified Sep 18, 2026

Try these checks on your own domain: Start a free scan. If a result needs a closer look, contact us.