The Caesar Cipher

From the Buttcrack Cipher Wiki — the free field guide to classical ciphers

The operation§

Write the alphabet twice and slide the lower copy by a fixed number of places. With a shift of three, A → D, B → E and Z → C. Every letter gets exactly the same treatment; punctuation and spaces are usually copied unchanged. That simple uniformity is both the cipher's appeal and its fatal weakness.

A tiny keyspace§

The key can be any number from 0 to 25. Shift 0 says nothing was encrypted, so there are only 25 meaningful alternatives. Try each decryption and score the result for English trigrams such as THE, ING and AND. The correct shift rapidly separates itself from the other 24.

Recognising a Caesar shift§

Word lengths, apostrophes, punctuation and repeated-letter patterns are unchanged. The most frequent ciphertext letter is often the encryption of E, and common short words remain the same shape. None of those clues is proof — a substitution cipher has similar surface properties — but a 26-shift sweep is so cheap that there is no reason to guess by eye.

History and legacy§

The cipher is named for Julius Caesar, who reportedly used a fixed shift in Roman military correspondence. Its modern value is educational: it demonstrates modular arithmetic, the difference between a keyspace and a strong keyspace, and the reason letter statistics matter. ROT13 survives as a convention for hiding spoilers, not for protecting secrets.

Next: learn why a repeating sequence of Caesar shifts is harder to spot in the Vigenère cipher guide.

Frequently asked questions§

What is the Caesar cipher formula?

With A equal to 0 through Z equal to 25, encryption is C = P + k mod 26 and decryption is P = C − k mod 26. The key k is the number of places rotated around the alphabet.

Is ROT13 a Caesar cipher?

Yes. ROT13 uses k = 13. Since 13 is exactly half of 26, encryption and decryption are the same operation: applying ROT13 twice returns the original text.

Why is it not secure?

There are only 26 possible rotations, including the unchanged alphabet. A person can list them; a computer can score them all immediately. Frequency analysis is useful, but exhaustive search alone is enough.

The facts in this article are generated from buttcrack's cipher registry when the site is built, so they describe the implementation you can run on this page. Registry-generated content is checked against the code; the history is editorial.

Try it live — break a real puzzle

Private by design

Drop in a puzzle. Leave with an answer.

Runs on this device
Try a sample
What this browser solver can—and cannot—do

It tries: Caesar, Atbash, ROT13, affine, Trithemius, rail fence, single-byte XOR, periodic Vigenère-family ciphers, autokey, selected encoding layers (such as Base64, hex, binary, decimal ASCII, Morse, and reverse), and—only with 60+ A–Z letters—statistical substitution.

It does not: prove a decryption, cover every classical cipher, or break modern encryption such as AES or RSA. Its ranking model is tuned for English, so a high score is a lead to verify with the method, key, and source context—not a guarantee.

Short text, non-English plaintext, non-Latin or symbol alphabets, missing keys, and unsupported formats can all leave no high-confidence answer. When that happens, the result includes input-specific observations and suggested next checks; those observations are not a claim to know the exact cause.

No account. No upload. No stored text. The complete solver runs in your browser.

This tool is free and has no account, no upload, no tracking of your text

Everything runs in your browser. If it saved you time, keeping it alive costs nothing but a click.