How the Caesar cipher works
Each letter is moved a fixed number of places along the alphabet. With a shift of 3,
A becomes D, B becomes E, and
Z wraps around to C. Decryption shifts back by the same amount.
Non-letters are left untouched, which is why punctuation and word lengths survive — and
why the cipher is so easy to break.
Why it falls instantly
The key is a single number between 0 and 25. That is the entire keyspace: 26 possibilities, 25 of which are wrong. A computer checks all of them in under a millisecond. The only real work is deciding which output is English, and a trigram model does that reliably on anything longer than a short phrase.
Breaking it by hand
If you want to do it yourself, count letters. E is the most common letter
in English by a wide margin, so whichever letter dominates your ciphertext is probably
E; the distance between them is your shift. Failing that, look for one-letter
words, which are almost always A or I, and three-letter words,
which are overwhelmingly THE.
Where you'll meet it
Caesar shifts turn up in escape rooms, geocache puzzles, beginner CTF challenges, treasure hunts and children's puzzle books. They are also frequently the innermost layer of a harder puzzle, wrapped in base64 or hex to disguise the fact that the underlying cipher is trivial — which is why this page still runs the full layered search rather than only trying shifts.
Frequently asked questions
How do I decode a Caesar cipher without the key?
There are only 26 possible shifts, so you try them all and pick the one that produces English. This page automates both halves: it generates all 26 candidates and scores each with a trigram language model, so the correct shift is chosen without you reading through the list.
Is ROT13 the same thing?
ROT13 is a Caesar cipher with a shift of exactly 13. Because 13 is half of 26, applying it twice returns the original text, which is why it is used for hiding spoilers rather than for security.
What is the difference between Caesar and Atbash?
Caesar rotates the alphabet by a fixed amount. Atbash reflects it, mapping A to Z, B to Y and so on. Atbash has no key at all, so there is only one possible decryption. This tool tests both.
The shift looks right but some words are wrong. Why?
A Caesar cipher applies one shift to the whole message, so if part of it decodes and part does not, you are probably looking at a Vigenère cipher, which uses a repeating sequence of shifts. Try the Vigenère page.