A Caesar cipher replaces each letter in a message with the letter a fixed number of positions later in the alphabet. With a shift of 3, A becomes D, B becomes E, Z wraps around to C. The word HELLO becomes KHOOR. This is the oldest documented substitution cipher: according to Encyclopaedia Britannica, the Roman historian Suetonius recorded that Julius Caesar used a shift of 3 to protect military correspondence.
How It Works
Think of the alphabet arranged in a circle. Encryption moves each letter clockwise by the shift amount; decryption moves it back counterclockwise by the same amount.
Mathematically, if you assign A=0, B=1, … Z=25:
- Encrypt: ciphertext position = (plaintext position + shift) mod 26
- Decrypt: plaintext position = (ciphertext position - shift + 26) mod 26
Encoding “HELLO” with Shift 3
| Letter | Position | + 3 | New position | Cipher |
|---|---|---|---|---|
| H | 7 | 10 | 10 | K |
| E | 4 | 7 | 7 | H |
| L | 11 | 14 | 14 | O |
| L | 11 | 14 | 14 | O |
| O | 14 | 17 | 17 | R |
HELLO → KHOOR. To decrypt KHOOR, subtract 3 from each position: K(10)→H(7), H(7)→E(4), O(14)→L(11), O(14)→L(11), R(17)→O(14). Result: HELLO.
Use the Caesar cipher tool to encrypt or decrypt any message with any shift.
The Full Alphabet at Shift 3
| Plain | A B C D E F G H I J K L M N O P Q R S T U V W X Y Z |
|---|---|
| Cipher | D E F G H I J K L M N O P Q R S T U V W X Y Z A B C |
ROT13: The Special Case of Shift 13
With a shift of 13, the cipher is its own inverse because the alphabet has 26 letters and 13 + 13 = 26. Encrypting HELLO with ROT13 gives URYYB; encrypting URYYB with ROT13 gives back HELLO. Online forums use ROT13 to hide spoilers and joke punchlines — it requires a deliberate action to reveal the text, but everyone knows the key.
Historical Use
The Caesar cipher is documented in Encyclopaedia Britannica and Suetonius’ Lives of the Twelve Caesars, which records that Caesar’s nephew Augustus used a shift of one (without wraparound). Cryptography historian David Kahn, in The Codebreakers (Scribner, 1996), notes that the cipher was still used by the Russian army in World War I, where German and Austrian cryptanalysts broke it without difficulty.
In 2006, Sicilian mafia boss Bernardo Provenzano was captured partly because messages encrypted with a number-based Caesar variant were decoded by investigators.
Limitations
- Only 25 distinct keys. A computer exhausts all possibilities in milliseconds.
- Frequency analysis. In English text, E is the most common letter (about 12.7% of text). If you find the most common ciphertext letter, it is almost certainly the encryption of E, which reveals the shift immediately.
- No protection against known-plaintext attacks. If an attacker knows any word in the original message, they can determine the shift instantly.
Caesar Cipher in Everyday Life
Beyond puzzle books and escape rooms, the Caesar cipher appears in several real contexts:
- ROT13 is standard in online communities for hiding spoilers. Reddit and many forums support
rot13.comlinks. The convention is well established even though everyone knows the “key.” - Decoder rings sold as children’s toys throughout the 20th century used a rotating wheel implementing a Caesar cipher, often at a fixed shift printed on the packaging.
- Number-based variants replace letters with numbers before shifting. The 2006 capture of Sicilian mafia boss Bernardo Provenzano was aided in part by the decryption of messages using a number-based Caesar variant.
Choosing a Shift
Any shift from 1 to 25 works. Shift 13 (ROT13) has the special property of being self-inverse. Shifts 3 and 13 are most common in puzzles. For any serious communication, no shift matters — all 25 are equally weak against brute force.
If you want to test your own message, use the Caesar cipher tool — paste your text and the tool shows the result at any shift from 1 to 25.
See How to Crack a Caesar Cipher for step-by-step breaking techniques, or Vigenère Cipher Explained to see how a keyword-based cipher partially overcomes these weaknesses.