You looked at your certificate and there are names on it belonging to companies you have never heard of.
This is almost always mundane. Certificates can list many names in their subject alternative name field, and shared hosting platforms, CDNs, and website builders routinely put dozens of customers on a single certificate rather than issuing one each. Your site and a stranger’s site are served by the same infrastructure, so they share the certificate that infrastructure presents.
When it is expected
| Situation | Why it happens |
|---|---|
| Shared hosting or a website builder | One certificate covers many customer domains on the same edge |
| A CDN on a shared plan | The edge presents a bundled certificate unless you pay for a dedicated one |
| A SaaS product with custom domains | Your subdomain rides along with other tenants’ custom domains |
| A platform’s default certificate | You are hitting a fallback certificate rather than one configured for your name |
If you are on a managed platform and never handled a private key yourself, this is the expected arrangement and not a finding.
When it deserves a question
Worth following up if any of these apply:
- You run your own infrastructure and issue your own certificates. Nobody else should be on them.
- The other names look like a former parent company, an old brand, or an agency you no longer work with. That points at a deployment nobody has revisited.
- You are on a plan you believed included a dedicated certificate.
- The names appear on an endpoint you did not know existed.
In each case the question is the same and it is a short one: who controls this certificate and its private key, and is that still the arrangement you intended?
What being listed does and does not mean
Being named on a certificate does not give the other party access to anything of yours. There is no capability attached to appearing in a SAN list.
What matters is the private key, and on a shared certificate that key belongs to the platform operator. They can already terminate TLS for your domain, which is inherent to using them. The other customers on the list cannot.
It also does not establish common ownership in the other direction. Two names on one certificate means one operator, not one company.
Reduce the surprise next time
A CAA record restricts which certificate authorities may issue for your domain at all, which limits how a certificate you did not expect can come into existence. It is a few DNS records and it is the most direct control you have here. See CAA certificate issuance policies, and check the renewal path before narrowing it.
If you want a dedicated certificate, most platforms offer one, often on a higher tier.
For how these relationships appear in a report and why the scope stays with the domain you submitted, see adjacent domains and certificate relationships.