Phishiest Certificate Authorities
Top 10 based on active phishing incidents using certificates with reviewable hostnames
This table show the top 10 phishiest certificate authorities, based on the number of currently blocked phishing sites with an associated valid, trusted SSL certificate where the CA has had a chance to review the deceptive domain name or host name. For example, we do not include a block of borclays.netcraft.com as the associated certificate is valid for *.netcraft.com.
Find out more about Netcraft's Services for Certificate Authorities, including Phishing Alerts for CAs and Deceptive Domain Scoring.
Certificate Authority | Currently Blocked Phishing Certificates |
---|---|
Let's Encrypt | 7,692 |
Sectigo | 7,118 |
DigiCert | 3,534 |
ZeroSSL | 279 |
GlobalSign | 39 |
Actalis | 36 |
GoDaddy | 26 |
GoGetSSL | 25 |
Amazon | 14 |
12 |
Note: Authorities are ranked by the number of certificates blocked.
This graphs shows the number of phishing SSL certificates used by blocked phishing sites on each day over the last year, broken down by CA. Certificates only count for the days in which their associated phishing site is included in the Netcraft Phishing Site Feed, and the certificate has neither expired nor been revoked.