Find matching SSH known-host records
Search a local known_hosts file for a supplied host and port, with match explanations and supported public-key fingerprints.
- 1Add input
- 2Adjust settings
- 3Get your result
Tool input and files are processed in this browser without being uploaded.
Before you start
Paste or select your saved OpenSSH known_hosts records, then supply the exact host and port you want to inspect. Find every applicable plain, wildcard or salted-hash record, including revoked and certificate-authority markers. The report explains why a row matches; it does not connect to that host or make a trust decision.
How to use this tool
- Paste the records or select one local known_hosts file, then enter the host and port.
- Search and review every match, its physical line, marker and explanation. A matching revoked record remains visible.
- Download the full JSON/CSV, compare the supported public-key fingerprint with separately trusted evidence, and keep the original file.
Supported inputs and limits
One UTF-8 file or pasted text, up to 1 MiB, 10,000 physical lines and 8,192 UTF-8 bytes per line. Blank and whole-line # comments are ignored. A selected file takes precedence; clear it to use pasted text. UTF-8 BOM and CRLF are accepted, other control characters are rejected.
Supply a bare ASCII hostname, IPv4 spelling or IPv6 address, with a separate integer port 1–65535. Port 22 uses the supplied host; other ports use [host]:port. Plain comma-separated patterns support * and ? and matching ! negation, case-insensitively, with at most 32 patterns per line and 5,000,000 pattern comparisons.
OpenSSH |1| salted HMAC-SHA1 host hashes require canonical padded Base64 and 20-byte salt/digest. They are compared against the exact supplied query case. Unknown hashes are not reversed, alternative hash versions and markers are unsupported.
Only matching ssh-ed25519 and ssh-rsa public-key blobs are structurally parsed and given SHA256 fingerprints. Any matching unsupported or malformed key rejects the result. Unmatched key bytes remain explicitly unvalidated; no private-key, signature, certificate-chain or remote-host validation occurs.
All original record lines and match explanations are retained in the complete JSON. CSV contains every matching line and fingerprint, with formula-like cells protected by default. The table previews 200 matching rows on 100-row pages; on-page text is a bounded report preview. Combined downloads are capped at 10 MiB atomically.
Worked example
Example input
demo.example,192.0.2.10 ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAABAgMEBQYHCAkKCwwNDg8QERITFBUWFxgZGhscHR4f plain *.example,!blocked.example ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAABAgMEBQYHCAkKCwwNDg8QERITFBUWFxgZGhscHR4f wildcard @revoked demo.example ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAABAgMEBQYHCAkKCwwNDg8QERITFBUWFxgZGhscHR4f revoked
Example options
{"hostname":"demo.example","port":22}Example output
3 saved records, 3 applicable rows, 1 revoked marker; parsed public key SHA256:ZkAslGjFiUHdGf/WUL8rQvkib4PTvQatUV0OUQSncCA. No network or trust decision.
When something does not work
Correct the first invalid physical line, unsupported marker or matching key, then run again. For no matches, check the supplied spelling and nondefault port; do not interpret an empty result as permission to trust the host.
Frequently asked questions
Can this reveal an unknown hashed hostname?
No. It tests only the name and port you supply against the stored salt and HMAC. No dictionary search, DNS lookup or SSH connection runs.
Does a matching CA or fingerprint mean the host is trusted?
No. @cert-authority and @revoked are reported as saved record markers. The fingerprint identifies parsed public-key bytes; its provenance, certificate signatures and current host key remain unverified.
Why can changing letter case affect a hash match?
Plain OpenSSH host patterns match without letter case. A stored salted hash is checked against the exact supplied query bytes, so enter the spelling you intend to search; the tool does not invent canonical variants.
Documentation & further reading
Related tools
IPv4 subnet and netmask calculator
Calculate IPv4 subnet boundaries and usable endpoints, or convert a netmask and prefix.
IP range to CIDR
Turn an inclusive IPv4 address range into the smallest exact list of CIDR blocks.
Aggregate CIDR blocks
Reduce an IPv4 CIDR list without changing its address coverage.
IPv4 number converter
Convert one IPv4 address between dotted decimal, unsigned integer and 32-bit binary.