Certificate Transparency

Every certificate for your domain is already public

Publicly-trusted certificates must be published to open, append-only logs before browsers will accept them. That makes mis-issuance detectable — but only by whoever is reading. Certificate Transparency Monitoring reads them for you and tells you the moment a certificate appears in your name.

What's at Stake

A certificate in your name doesn't have to be yours.

Issuance is not centralised. Any of a large number of authorities can produce a valid certificate for a name you own, given a validation they are satisfied with — a DNS record that was briefly wrong, an email alias someone else controls, an internal team going around procurement, or an outright mis-issuance. Browsers will trust the result. The only reason you can find out at all is that the certificate has to be logged publicly, and the only way that helps is if somebody is reading the logs on your behalf.

Distributed Trust

Many authorities can issue for your name

Your certificate provider is your choice, not a restriction. Nothing stops a different authority issuing for the same domain if it believes the request is legitimate, and your own provider will never hear about it.

Shadow Issuance

Certificates appear that nobody logged a ticket for

A team spinning up a staging environment, a supplier hosting a microsite for you, an old platform still auto-renewing. Most are legitimate and none are recorded anywhere you look — until an audit asks what exists and nobody can answer.

Read by Others

Attackers already watch these logs

Newly-issued certificates announce new infrastructure, so the logs are routinely mined to find staging hosts and internal tools the moment they get a certificate. That intelligence about your estate is public. Not reading it yourself is a choice.

What CT Monitoring Does

Tell us your domains. We'll watch the logs.

Add the names you care about and we monitor the public Certificate Transparency logs for anything issued against them, alerting you when something new appears.

Issuance Alerts

Told when a certificate is logged in your name

Each time a certificate or pre-certificate for one of your monitored domains reaches the logs, it appears in your account and, if you want it, in your inbox. Pre-certificates matter here: they are logged before the certificate itself is issued, so the warning arrives at the earliest possible moment rather than after deployment.

Learn more about CT Monitoring →
Policy Auditing

Check what was issued against what you allow

Once every certificate is visible, the useful questions become answerable. Is this authority one we actually use? Does this hostname belong to a system we know about? Has something been issued for a name that should never have a public certificate at all? An inventory you did not have to assemble is what makes those checks possible.

Learn more about SMTP TLS Reports →
Phishing Discovery

New certificates are the earliest sign of a lookalike

Sites impersonating you need certificates too, and those certificates are logged like any other. Monitoring names close to your own turns the logs into an early warning about infrastructure being prepared against you — often while the site is still being built rather than after your customers have found it.

Learn more about Threat Intelligence →
Get Started

The logs are public. Start reading yours.

Nothing to deploy. Add your domains and monitoring starts immediately.

30-day free trial  ·  No deployment  ·  No code  ·  Cancel anytime

Detection

What a log entry tells you

A certificate is a public statement about your infrastructure. Read in aggregate, the entries answer questions about your estate that are otherwise surprisingly hard to settle.

Observed What it tells you
An unfamiliar issuing authority A certificate obtained outside your normal provider or process
A hostname you don't recognise Infrastructure someone stood up without telling anyone
A pre-certificate Issuance in progress — the earliest warning available
An internal name made public A system that was never meant to have a public certificate
A name close to your own Infrastructure being prepared to impersonate you
A renewal you didn't schedule An old platform still alive and still auto-renewing

Most entries will be routine, and that is the point — a list of expected renewals is what makes the one unexpected entry visible.

Architecture

Nothing to deploy at all.

This is the one product on the platform that touches nothing you run. There is no header, no DNS record, no policy file and no configuration on your servers — the data already exists in public logs, and the only thing we need from you is which names to watch.

Add your domains and monitoring begins. Enable email alerts and you are told as entries appear rather than when you next log in.

Setup — the domains to monitor, added in your account
example.com
example.co.uk
example-support.com

Monitoring names adjacent to your own is worth doing deliberately — they are where impersonation gets prepared, and they cost nothing extra to watch.

No code, no header, no DNS record

Nothing changes on your servers

Works for domains you don't host yourself

Covers certificates issued by anyone, not just your provider

Monitoring starts the moment the list is saved

Identity

Certificates are one of three ways your name gets used

A certificate lets someone present themselves as your domain to a browser. DMARC governs whether they can present themselves as your domain in email. SMTP TLS governs whether the connection carrying that mail was encrypted at all. Each is a different route to the same outcome, and each is observable if you are collecting the right public signal.

Certificate Transparency is the cheapest of the three to start, because there is nothing to deploy before it works.

Scope

One layer in the stack. Here's how it fits.

CT Monitoring tells you what certificates exist for your names. It does not issue or revoke them, and it does not tell you what the sites using them are doing — it is the issuance visibility layer, and it works alongside the rest.

CT Monitoring does Pairs with
Alerts on certificates issued in your name DMARC for your name being used in email
Surfaces infrastructure nobody recorded Network Error Logging for certificate problems your visitors hit
Reveals lookalike domains being prepared Threat Intelligence for known malicious infrastructure
Audits issuance against your own policy SMTP TLS Reports for transport security between mail servers

Together, these cover the ways your organisation's identity can be claimed by somebody else — in certificates, in mail, and in transport.