Support
Loading...

Check Certificate Transparency for Unexpected Domain Certificates

7 October 2026

Certificate Transparency can reveal new HTTPS certificates for your domains. Set up monitoring, compare alerts with your approved services, and investigate issuance you do not recognize.

Why look beyond the certificate in your browser?

The certificate currently served by your website shows only one part of the picture. Certificate Transparency (CT) logs make issuance of publicly trusted web certificates visible. A certificate issued for your domain might never appear on your own server, so checking the live site alone can miss it. CT monitoring helps you notice new issuance and ask whether it was authorized; an alert is a lead to investigate, not proof of an attack.

Build the list you want to monitor

Start with every domain your organization controls, including regional names, parked domains, and domains used only for email or redirects. Include the subdomains that matter to your business. Keep a record of who operates each website, CDN, or certificate automation service. That list helps explain legitimate certificates when an alert arrives.

Turn on certificate alerts

Choose a CT monitoring service that can watch your domain portfolio and notify you when a certificate or precertificate appears in the public logs it checks. Confirm which names it covers, where alerts go, and who will review them. CT logs are public, but monitoring is most useful when someone owns the follow-up. Do not assume a monitoring service covers every log or sends an alert instantly.

Triage an unfamiliar certificate

Read the names on the certificate, its issuer and its issuance time. Compare them with recent renewals, hosting changes, CDN settings and services authorized to request certificates. A provider may legitimately issue a new certificate without your team requesting it by hand. If the certificate still cannot be explained, contact the provider or certificate authority and review your domain’s authoritative DNS and account access. If issuance was unauthorized, work with the issuing authority on revocation and follow your incident-response process. Avoid changing DNS or revoking a certificate until you know which service depends on it.

CT monitoring complements routine HTTPS checks; it does not replace them. Test the public addresses your visitors use, as described in our website HTTPS checklist. If a certificate alert leads you to inspect your domain’s DNS, our DNS troubleshooting guide explains how to distinguish authoritative records from cached answers. See the SSL certificate options at NicNames when you need a certificate for a site you operate.

Share this article:
Ask Jexi