Site AI Auditvon Internet Solutions

Certificate Transparency Logs: Every Certificate for Your Domain

20. September 20267 Min. LesezeitSicherheit & SSL
Certificate Transparency Logs: Every Certificate for Your Domain

Short answer: Certificate Transparency (CT) is a system of public, append-only logs in which certificate authorities must record every publicly trusted SSL/TLS certificate; browsers such as Chrome and Safari reject certificates that are not logged. For site owners, CT means you can search the logs to see every certificate ever issued for your domain and subdomains, discover forgotten services, spot certificates from unexpected authorities, and set up alerts for new certificates. It is a free early-warning system for mis-issuance and a useful inventory tool.

Certificate authorities are trusted to issue certificates only to the rightful owners of domains. Historically, when a CA made a mistake or was compromised, nobody might notice for months. Certificate Transparency was created to make every issuance visible, so mistakes and abuse can be detected quickly by anyone – including you. Most website owners have never looked at the logs for their own domain, yet doing so takes a minute and often reveals something interesting. This guide explains what CT is, how to use it and what to do with what you find.

How Certificate Transparency works

  1. Before or while issuing a certificate, the CA submits it (or a precertificate) to several independent CT logs.
  2. Each log returns a signed promise to include it, called a Signed Certificate Timestamp (SCT).
  3. The SCTs are embedded in the certificate or delivered during the TLS handshake.
  4. Browsers that enforce CT check for valid SCTs and reject certificates that lack them.
  5. Logs are append-only and cryptographically verifiable, so entries cannot be quietly removed.
  6. Monitors and search services read the logs and make them searchable.

The result: any publicly trusted certificate that works in major browsers is, in practice, publicly listed. The system is described in RFC 6962 and its successors.

For site owners the important consequence is simple: a certificate for your domain cannot be issued secretly if it is to work in mainstream browsers. If someone obtains one – through a CA error, a hijacked DNS account or a taken-over subdomain – it will appear in the logs within minutes to hours, where you or a monitoring service can see it.

What you can learn from the logs

How to search the logs

Several free web services index CT logs and let you search by domain. Popular options include crt.sh and the certificate search tools offered by some CDN and security vendors. A typical search:

  1. Enter your domain, often with a wildcard such as %.example.com to include subdomains.
  2. Sort by issue date to see the most recent certificates first.
  3. Review the columns for hostnames (common name and SAN entries), issuer and validity dates.
  4. Filter out expired certificates if you only want the current picture, or keep them to see history.

Expect to see duplicates: precertificates and final certificates are both logged, and certificates are renewed regularly, so a single hostname can appear many times.

What to look for

What you seePossible meaningAction
Subdomain you do not recogniseForgotten service, agency setup or vendor toolFind the owner; remove DNS if unused
Issuer you do not useA vendor issuing for a hosted subdomain, or mis-issuanceCheck which service it belongs to; contact the CA if unexplained
Recent certificate for an old campaign subdomainThe subdomain may be in use by someone elseInvestigate for a possible subdomain takeover
Renewals stopped months ago for a live hostnameCertificate may be expired or served by another providerCheck the site directly
Certificates for lookalike domainsPossible phishing preparationConsider reporting to the registrar or hosting provider

Most unexpected entries have innocent explanations – a help desk platform, a marketing tool, a CDN that uses multiple CAs. The point is to know each one.

Setting up alerts for new certificates

Searching once is useful; being notified automatically is better. Several services, some of them free, watch CT logs and send an e-mail when a new certificate appears for your domains. When choosing one:

CT and privacy: your subdomains are public

A side effect of CT is that every hostname on a publicly trusted certificate is visible to anyone, including attackers doing reconnaissance. Names like vpn.example.com, jenkins.example.com or staging-newshop.example.com tell a story. This is not a reason to avoid certificates – HTTPS everywhere is far more important – but it is a reason not to rely on obscure hostnames for protection. Internal tools should require authentication and ideally be reachable only from trusted networks. Wildcard certificates reveal only the pattern, but hide names at the cost of sharing one key across services, which has its own drawbacks.

Using CT during incidents and migrations

CT logs are a practical tool in several situations beyond routine checks:

A ten-minute review you can do today

  1. Search the logs for your main domain including subdomains, and export or copy the list of distinct hostnames from the last two years.
  2. Mark each hostname as “in use”, “retired” or “unknown”. Ask colleagues and agencies about the unknown ones.
  3. For every retired hostname, check whether its DNS record still exists. If it does and points to an external service, remove it or reclaim the service.
  4. List the certificate authorities that appear, and note which service each belongs to.
  5. Check that every hostname in use has a recent certificate. A live hostname whose last certificate is months old may be serving an expired one.
  6. Save the list as the start of a simple domain inventory and repeat the review each quarter.

Many organisations find at least one forgotten subdomain on the first review – which is exactly the kind of loose end attackers look for.

Limits of Certificate Transparency

CT makes issuance visible; it does not prevent it. A mis-issued certificate is still valid until someone notices and it is revoked. CT also covers only publicly trusted certificates: private CAs, self-signed certificates and internal certificates are not logged. And it only helps if someone looks, which is why alerts and regular reviews matter. Combine CT monitoring with CAA records to limit which CAs may issue, strong security on DNS and registrar accounts, and external monitoring of the certificates your visitors actually receive.

How Site AI Audit helps

CT tells you which certificates exist; Site AI Audit tells you what your visitors actually get. Each check verifies the SSL certificate on your site, its expiry date and the HTTP to HTTPS redirect, along with security headers and exposed software versions, with plain-language fixes. Monitoring on paid plans alerts you before a certificate expires. Run a free check.

Related reading

The bottom line

Certificate Transparency makes every publicly trusted certificate visible, and that visibility works for you. Search the logs for your domain to build an inventory of hostnames and issuers, investigate anything unfamiliar, and set up alerts for new certificates. Treat the hostnames in your certificates as public, and combine CT with CAA records, secure DNS accounts and monitoring of the certificates your visitors see.

FAQ

Can I remove my certificates from CT logs?

No. The logs are append-only by design, so entries cannot be removed. That permanence is what makes them trustworthy for detecting mis-issuance.

Do I need to do anything to get my certificates logged?

No. Certificate authorities log publicly trusted certificates automatically, because major browsers reject certificates without valid CT proofs.

Why do I see the same certificate twice in the logs?

CAs usually log a precertificate before issuing the final certificate, and both appear in search results. Renewals also create new entries for the same hostnames.

Is it a security risk that my subdomains are visible in CT logs?

It reveals names, not access. Any service that depends on its hostname staying secret is already at risk, so protect internal services with authentication and network restrictions instead.

How often should I check CT logs for my domain?

Set up automatic alerts if possible. Otherwise, review the logs quarterly and whenever you suspect an incident, add a CAA record or plan a DNS or hosting migration.

#SSL certificate#TLS#Website security
Prüfen Sie Ihre eigene Website — kostenlos.Was Sie auf Ihrer Website beheben sollten — und wo Sie anfangen.
Kostenlos starten

Mehr aus dem Blog

Alle Artikel →
Internet Solutions

Mehr von unserem Team

Entwickelt von Internet Solutions. Probieren Sie auch unsere anderen Produkte aus — jedes spart Ihnen auf seine eigene Weise Zeit.

internet-solutions.net ↗
Site AI Audit
Datenschutz-Übersicht

Diese Website verwendet Cookies, damit wir Ihnen die bestmögliche Nutzererfahrung bieten können. Cookie-Informationen werden in Ihrem Browser gespeichert und erfüllen Funktionen wie das Wiedererkennen bei Ihrem nächsten Besuch und helfen unserem Team zu verstehen, welche Bereiche der Website Sie am interessantesten und nützlichsten finden.