Phishiest Certificate Authorities

This table show the top 10 phishiest certificate authorities, based on the number of currently blocked phishing sites with an associated valid, trusted SSL certificate where the CA has had a chance to review the deceptive domain name or host name. For example, we do not include a block of borclays.netcraft.com as the associated certificate is valid for *.netcraft.com.

Find out more about Netcraft's Services for Certificate Authorities, including Phishing Alerts for CAs, Deceptive Domain Scoring, and Pre-Issuance certificate checking.

Certificate Authority Phishing Certificates Currently Blocked
Let's Encrypt 6244
Comodo 3293
GoDaddy 124
Symantec 44
GlobalSign 38
STRATO AG 19
TrustAsia Technologies, Inc. 16
Actalis S.p.A./03358520967 13
CloudFlare, Inc. 3
DigiCert 2

Note: Authorities are ranked by the number of certificates blocked.

This graph shows the number of phishing SSL certificates on each day over the last year, broken down by CA.