Short answer: Certificate Transparency (CT) is a system of public, append-only logs in which certificate authorities must record every publicly trusted SSL/TLS certificate; browsers such as Chrome and Safari reject certificates that are not logged. For site owners, CT means you can search the logs to see every certificate ever issued for your domain and subdomains, discover forgotten services, spot certificates from unexpected authorities, and set up alerts for new certificates. It is a free early-warning system for mis-issuance and a useful inventory tool.
Certificate authorities are trusted to issue certificates only to the rightful owners of domains. Historically, when a CA made a mistake or was compromised, nobody might notice for months. Certificate Transparency was created to make every issuance visible, so mistakes and abuse can be detected quickly by anyone – including you. Most website owners have never looked at the logs for their own domain, yet doing so takes a minute and often reveals something interesting. This guide explains what CT is, how to use it and what to do with what you find.
How Certificate Transparency works
- Before or while issuing a certificate, the CA submits it (or a precertificate) to several independent CT logs.
- Each log returns a signed promise to include it, called a Signed Certificate Timestamp (SCT).
- The SCTs are embedded in the certificate or delivered during the TLS handshake.
- Browsers that enforce CT check for valid SCTs and reject certificates that lack them.
- Logs are append-only and cryptographically verifiable, so entries cannot be quietly removed.
- Monitors and search services read the logs and make them searchable.
The result: any publicly trusted certificate that works in major browsers is, in practice, publicly listed. The system is described in RFC 6962 and its successors.
For site owners the important consequence is simple: a certificate for your domain cannot be issued secretly if it is to work in mainstream browsers. If someone obtains one – through a CA error, a hijacked DNS account or a taken-over subdomain – it will appear in the logs within minutes to hours, where you or a monitoring service can see it.
What you can learn from the logs
- Every hostname with a certificate – including subdomains you forgot about: old campaigns, staging servers, test tools, vendor-hosted services.
- Which authorities issue for your domain – useful before adding a CAA record, and for spotting an issuer you do not recognise.
- Renewal history – whether certificates are being renewed on schedule, or whether renewals suddenly stopped.
- Unexpected certificates – issued by a CA you do not use, for a name you did not request, or at a time when nobody on your team made changes.
- Shadow IT – services set up by other departments or agencies that obtained certificates for your domain.
How to search the logs
Several free web services index CT logs and let you search by domain. Popular options include crt.sh and the certificate search tools offered by some CDN and security vendors. A typical search:
- Enter your domain, often with a wildcard such as
%.example.comto include subdomains. - Sort by issue date to see the most recent certificates first.
- Review the columns for hostnames (common name and SAN entries), issuer and validity dates.
- Filter out expired certificates if you only want the current picture, or keep them to see history.
Expect to see duplicates: precertificates and final certificates are both logged, and certificates are renewed regularly, so a single hostname can appear many times.
What to look for
| What you see | Possible meaning | Action |
|---|---|---|
| Subdomain you do not recognise | Forgotten service, agency setup or vendor tool | Find the owner; remove DNS if unused |
| Issuer you do not use | A vendor issuing for a hosted subdomain, or mis-issuance | Check which service it belongs to; contact the CA if unexplained |
| Recent certificate for an old campaign subdomain | The subdomain may be in use by someone else | Investigate for a possible subdomain takeover |
| Renewals stopped months ago for a live hostname | Certificate may be expired or served by another provider | Check the site directly |
| Certificates for lookalike domains | Possible phishing preparation | Consider reporting to the registrar or hosting provider |
Most unexpected entries have innocent explanations – a help desk platform, a marketing tool, a CDN that uses multiple CAs. The point is to know each one.
Setting up alerts for new certificates
Searching once is useful; being notified automatically is better. Several services, some of them free, watch CT logs and send an e-mail when a new certificate appears for your domains. When choosing one:
- Make sure it covers subdomains, not only the exact domain.
- Send alerts to a team address, not a single person’s inbox.
- Expect regular alerts from normal renewals; with automated 90-day certificates, each hostname generates several per year. Some services can filter known issuers.
- Agree on what the recipient should do when an alert looks unfamiliar.
CT and privacy: your subdomains are public
A side effect of CT is that every hostname on a publicly trusted certificate is visible to anyone, including attackers doing reconnaissance. Names like vpn.example.com, jenkins.example.com or staging-newshop.example.com tell a story. This is not a reason to avoid certificates – HTTPS everywhere is far more important – but it is a reason not to rely on obscure hostnames for protection. Internal tools should require authentication and ideally be reachable only from trusted networks. Wildcard certificates reveal only the pattern, but hide names at the cost of sharing one key across services, which has its own drawbacks.
Using CT during incidents and migrations
CT logs are a practical tool in several situations beyond routine checks:
- After a suspected compromise: look for certificates issued during the incident window that you did not request; they could let attackers impersonate your site even after cleanup, and should be revoked.
- Before a DNS or CDN migration: list every hostname with a certificate so nothing is forgotten in the move.
- When taking over a client or a new domain: agencies and new IT staff can build an initial inventory of services from the logs in minutes.
- When adding a CAA record: see which CAs issued for your domain in the last year, so the record does not block legitimate renewals.
A ten-minute review you can do today
- Search the logs for your main domain including subdomains, and export or copy the list of distinct hostnames from the last two years.
- Mark each hostname as “in use”, “retired” or “unknown”. Ask colleagues and agencies about the unknown ones.
- For every retired hostname, check whether its DNS record still exists. If it does and points to an external service, remove it or reclaim the service.
- List the certificate authorities that appear, and note which service each belongs to.
- Check that every hostname in use has a recent certificate. A live hostname whose last certificate is months old may be serving an expired one.
- Save the list as the start of a simple domain inventory and repeat the review each quarter.
Many organisations find at least one forgotten subdomain on the first review – which is exactly the kind of loose end attackers look for.
Limits of Certificate Transparency
CT makes issuance visible; it does not prevent it. A mis-issued certificate is still valid until someone notices and it is revoked. CT also covers only publicly trusted certificates: private CAs, self-signed certificates and internal certificates are not logged. And it only helps if someone looks, which is why alerts and regular reviews matter. Combine CT monitoring with CAA records to limit which CAs may issue, strong security on DNS and registrar accounts, and external monitoring of the certificates your visitors actually receive.
How Site AI Audit helps
CT tells you which certificates exist; Site AI Audit tells you what your visitors actually get. Each check verifies the SSL certificate on your site, its expiry date and the HTTP to HTTPS redirect, along with security headers and exposed software versions, with plain-language fixes. Monitoring on paid plans alerts you before a certificate expires. Run a free check.
Related reading
- Subdomain Takeover: How Forgotten DNS Records Get Hijacked
- CAA Records Explained: Control Who Can Issue Your Certificates
- SSL Certificate Revocation: When and How to Revoke a Certificate
The bottom line
Certificate Transparency makes every publicly trusted certificate visible, and that visibility works for you. Search the logs for your domain to build an inventory of hostnames and issuers, investigate anything unfamiliar, and set up alerts for new certificates. Treat the hostnames in your certificates as public, and combine CT with CAA records, secure DNS accounts and monitoring of the certificates your visitors see.
FAQ
Can I remove my certificates from CT logs?
No. The logs are append-only by design, so entries cannot be removed. That permanence is what makes them trustworthy for detecting mis-issuance.
Do I need to do anything to get my certificates logged?
No. Certificate authorities log publicly trusted certificates automatically, because major browsers reject certificates without valid CT proofs.
Why do I see the same certificate twice in the logs?
CAs usually log a precertificate before issuing the final certificate, and both appear in search results. Renewals also create new entries for the same hostnames.
Is it a security risk that my subdomains are visible in CT logs?
It reveals names, not access. Any service that depends on its hostname staying secret is already at risk, so protect internal services with authentication and network restrictions instead.
How often should I check CT logs for my domain?
Set up automatic alerts if possible. Otherwise, review the logs quarterly and whenever you suspect an incident, add a CAA record or plan a DNS or hosting migration.



