Publicly-trusted certificates must be published to open, append-only logs before browsers will accept them. That makes mis-issuance detectable — but only by whoever is reading. Certificate Transparency Monitoring reads them for you and tells you the moment a certificate appears in your name.
Issuance is not centralised. Any of a large number of authorities can produce a valid certificate for a name you own, given a validation they are satisfied with — a DNS record that was briefly wrong, an email alias someone else controls, an internal team going around procurement, or an outright mis-issuance. Browsers will trust the result. The only reason you can find out at all is that the certificate has to be logged publicly, and the only way that helps is if somebody is reading the logs on your behalf.
Your certificate provider is your choice, not a restriction. Nothing stops a different authority issuing for the same domain if it believes the request is legitimate, and your own provider will never hear about it.
A team spinning up a staging environment, a supplier hosting a microsite for you, an old platform still auto-renewing. Most are legitimate and none are recorded anywhere you look — until an audit asks what exists and nobody can answer.
Newly-issued certificates announce new infrastructure, so the logs are routinely mined to find staging hosts and internal tools the moment they get a certificate. That intelligence about your estate is public. Not reading it yourself is a choice.
Add the names you care about and we monitor the public Certificate Transparency logs for anything issued against them, alerting you when something new appears.
Each time a certificate or pre-certificate for one of your monitored domains reaches the logs, it appears in your account and, if you want it, in your inbox. Pre-certificates matter here: they are logged before the certificate itself is issued, so the warning arrives at the earliest possible moment rather than after deployment.
Learn more about CT Monitoring →Once every certificate is visible, the useful questions become answerable. Is this authority one we actually use? Does this hostname belong to a system we know about? Has something been issued for a name that should never have a public certificate at all? An inventory you did not have to assemble is what makes those checks possible.
Learn more about SMTP TLS Reports →Sites impersonating you need certificates too, and those certificates are logged like any other. Monitoring names close to your own turns the logs into an early warning about infrastructure being prepared against you — often while the site is still being built rather than after your customers have found it.
Learn more about Threat Intelligence →Nothing to deploy. Add your domains and monitoring starts immediately.
30-day free trial · No deployment · No code · Cancel anytime
A certificate is a public statement about your infrastructure. Read in aggregate, the entries answer questions about your estate that are otherwise surprisingly hard to settle.
| Observed | What it tells you |
|---|---|
| An unfamiliar issuing authority | A certificate obtained outside your normal provider or process |
| A hostname you don't recognise | Infrastructure someone stood up without telling anyone |
| A pre-certificate | Issuance in progress — the earliest warning available |
| An internal name made public | A system that was never meant to have a public certificate |
| A name close to your own | Infrastructure being prepared to impersonate you |
| A renewal you didn't schedule | An old platform still alive and still auto-renewing |
Most entries will be routine, and that is the point — a list of expected renewals is what makes the one unexpected entry visible.
This is the one product on the platform that touches nothing you run. There is no header, no DNS record, no policy file and no configuration on your servers — the data already exists in public logs, and the only thing we need from you is which names to watch.
Add your domains and monitoring begins. Enable email alerts and you are told as entries appear rather than when you next log in.
example.com
example.co.uk
example-support.com
Monitoring names adjacent to your own is worth doing deliberately — they are where impersonation gets prepared, and they cost nothing extra to watch.
A certificate lets someone present themselves as your domain to a browser. DMARC governs whether they can present themselves as your domain in email. SMTP TLS governs whether the connection carrying that mail was encrypted at all. Each is a different route to the same outcome, and each is observable if you are collecting the right public signal.
Certificate Transparency is the cheapest of the three to start, because there is nothing to deploy before it works.
CT Monitoring tells you what certificates exist for your names. It does not issue or revoke them, and it does not tell you what the sites using them are doing — it is the issuance visibility layer, and it works alongside the rest.
| CT Monitoring does | Pairs with |
|---|---|
| Alerts on certificates issued in your name | DMARC for your name being used in email |
| Surfaces infrastructure nobody recorded | Network Error Logging for certificate problems your visitors hit |
| Reveals lookalike domains being prepared | Threat Intelligence for known malicious infrastructure |
| Audits issuance against your own policy | SMTP TLS Reports for transport security between mail servers |
Together, these cover the ways your organisation's identity can be claimed by somebody else — in certificates, in mail, and in transport.