Site AI Auditby Internet Solutions

Certificate Transparency Logs: Every Certificate for Your Domain

20 tháng 9, 20267 phút đọcBảo mật & SSL
Certificate Transparency Logs: Every Certificate for Your Domain

Short answer: Certificate Transparency (CT) is a system of public, append-only logs in which certificate authorities must record every publicly trusted SSL/TLS certificate; browsers such as Chrome and Safari reject certificates that are not logged. For site owners, CT means you can search the logs to see every certificate ever issued for your domain and subdomains, discover forgotten services, spot certificates from unexpected authorities, and set up alerts for new certificates. It is a free early-warning system for mis-issuance and a useful inventory tool.

Certificate authorities are trusted to issue certificates only to the rightful owners of domains. Historically, when a CA made a mistake or was compromised, nobody might notice for months. Certificate Transparency was created to make every issuance visible, so mistakes and abuse can be detected quickly by anyone – including you. Most website owners have never looked at the logs for their own domain, yet doing so takes a minute and often reveals something interesting. This guide explains what CT is, how to use it and what to do with what you find.

How Certificate Transparency works

  1. Before or while issuing a certificate, the CA submits it (or a precertificate) to several independent CT logs.
  2. Each log returns a signed promise to include it, called a Signed Certificate Timestamp (SCT).
  3. The SCTs are embedded in the certificate or delivered during the TLS handshake.
  4. Browsers that enforce CT check for valid SCTs and reject certificates that lack them.
  5. Logs are append-only and cryptographically verifiable, so entries cannot be quietly removed.
  6. Monitors and search services read the logs and make them searchable.

The result: any publicly trusted certificate that works in major browsers is, in practice, publicly listed. The system is described in RFC 6962 and its successors.

For site owners the important consequence is simple: a certificate for your domain cannot be issued secretly if it is to work in mainstream browsers. If someone obtains one – through a CA error, a hijacked DNS account or a taken-over subdomain – it will appear in the logs within minutes to hours, where you or a monitoring service can see it.

What you can learn from the logs

How to search the logs

Several free web services index CT logs and let you search by domain. Popular options include crt.sh and the certificate search tools offered by some CDN and security vendors. A typical search:

  1. Enter your domain, often with a wildcard such as %.example.com to include subdomains.
  2. Sort by issue date to see the most recent certificates first.
  3. Review the columns for hostnames (common name and SAN entries), issuer and validity dates.
  4. Filter out expired certificates if you only want the current picture, or keep them to see history.

Expect to see duplicates: precertificates and final certificates are both logged, and certificates are renewed regularly, so a single hostname can appear many times.

What to look for

What you seePossible meaningAction
Subdomain you do not recogniseForgotten service, agency setup or vendor toolFind the owner; remove DNS if unused
Issuer you do not useA vendor issuing for a hosted subdomain, or mis-issuanceCheck which service it belongs to; contact the CA if unexplained
Recent certificate for an old campaign subdomainThe subdomain may be in use by someone elseInvestigate for a possible subdomain takeover
Renewals stopped months ago for a live hostnameCertificate may be expired or served by another providerCheck the site directly
Certificates for lookalike domainsPossible phishing preparationConsider reporting to the registrar or hosting provider

Most unexpected entries have innocent explanations – a help desk platform, a marketing tool, a CDN that uses multiple CAs. The point is to know each one.

Setting up alerts for new certificates

Searching once is useful; being notified automatically is better. Several services, some of them free, watch CT logs and send an e-mail when a new certificate appears for your domains. When choosing one:

CT and privacy: your subdomains are public

A side effect of CT is that every hostname on a publicly trusted certificate is visible to anyone, including attackers doing reconnaissance. Names like vpn.example.com, jenkins.example.com or staging-newshop.example.com tell a story. This is not a reason to avoid certificates – HTTPS everywhere is far more important – but it is a reason not to rely on obscure hostnames for protection. Internal tools should require authentication and ideally be reachable only from trusted networks. Wildcard certificates reveal only the pattern, but hide names at the cost of sharing one key across services, which has its own drawbacks.

Using CT during incidents and migrations

CT logs are a practical tool in several situations beyond routine checks:

A ten-minute review you can do today

  1. Search the logs for your main domain including subdomains, and export or copy the list of distinct hostnames from the last two years.
  2. Mark each hostname as “in use”, “retired” or “unknown”. Ask colleagues and agencies about the unknown ones.
  3. For every retired hostname, check whether its DNS record still exists. If it does and points to an external service, remove it or reclaim the service.
  4. List the certificate authorities that appear, and note which service each belongs to.
  5. Check that every hostname in use has a recent certificate. A live hostname whose last certificate is months old may be serving an expired one.
  6. Save the list as the start of a simple domain inventory and repeat the review each quarter.

Many organisations find at least one forgotten subdomain on the first review – which is exactly the kind of loose end attackers look for.

Limits of Certificate Transparency

CT makes issuance visible; it does not prevent it. A mis-issued certificate is still valid until someone notices and it is revoked. CT also covers only publicly trusted certificates: private CAs, self-signed certificates and internal certificates are not logged. And it only helps if someone looks, which is why alerts and regular reviews matter. Combine CT monitoring with CAA records to limit which CAs may issue, strong security on DNS and registrar accounts, and external monitoring of the certificates your visitors actually receive.

How Site AI Audit helps

CT tells you which certificates exist; Site AI Audit tells you what your visitors actually get. Each check verifies the SSL certificate on your site, its expiry date and the HTTP to HTTPS redirect, along with security headers and exposed software versions, with plain-language fixes. Monitoring on paid plans alerts you before a certificate expires. Run a free check.

Related reading

The bottom line

Certificate Transparency makes every publicly trusted certificate visible, and that visibility works for you. Search the logs for your domain to build an inventory of hostnames and issuers, investigate anything unfamiliar, and set up alerts for new certificates. Treat the hostnames in your certificates as public, and combine CT with CAA records, secure DNS accounts and monitoring of the certificates your visitors see.

FAQ

Can I remove my certificates from CT logs?

No. The logs are append-only by design, so entries cannot be removed. That permanence is what makes them trustworthy for detecting mis-issuance.

Do I need to do anything to get my certificates logged?

No. Certificate authorities log publicly trusted certificates automatically, because major browsers reject certificates without valid CT proofs.

Why do I see the same certificate twice in the logs?

CAs usually log a precertificate before issuing the final certificate, and both appear in search results. Renewals also create new entries for the same hostnames.

Is it a security risk that my subdomains are visible in CT logs?

It reveals names, not access. Any service that depends on its hostname staying secret is already at risk, so protect internal services with authentication and network restrictions instead.

How often should I check CT logs for my domain?

Set up automatic alerts if possible. Otherwise, review the logs quarterly and whenever you suspect an incident, add a CAA record or plan a DNS or hosting migration.

#SSL certificate#TLS#Website security
Hãy kiểm tra website của chính bạn — miễn phí.Website của bạn cần sửa gì — và nên bắt đầu từ đâu.
Bắt đầu miễn phí
Internet Solutions

Sản phẩm khác từ đội ngũ chúng tôi

Do Internet Solutions phát triển. Hãy thử các sản phẩm khác của chúng tôi — mỗi sản phẩm giúp bạn tiết kiệm thời gian theo một cách riêng.

internet-solutions.net ↗
01Tự động đăng mạng xã hội
PostRSS

Bài mới từ nguồn cấp RSS của bạn được tự động đăng lên Facebook, X, LinkedIn, Telegram và hơn 60 mạng khác.

Gói miễn phí · từ 2014Truy cập →
02Chat trực tuyến AI cho website
Talkmio

Website của bạn trả lời khách truy cập 24/7 từ chính nội dung của bạn, bằng ngôn ngữ của họ.

Gói miễn phí · không cần thẻTruy cập →
03Trợ lý AI
Ask Mio

Trò chuyện, viết code, thiết kế, viết bài và nghiên cứu. Mio chọn mô hình tốt nhất cho từng việc.

Gói miễn phíTruy cập →
04Lái tự động AI cho blog và mạng xã hội
AI Blog Autopilot

AI viết bài SEO dài 2.000–3.000 từ và chia sẻ từng bài lên hơn 58 mạng xã hội.

3 bài đầu tiên miễn phíTruy cập →
05Thu thập SEO chuyên sâu
Site SEO AI Audit

Thu thập SEO toàn diện trên 7 lĩnh vực, gồm cả khả năng hiển thị trong tìm kiếm AI, với cách sửa xếp theo mức tác động.

Lần kiểm tra đầu tiên miễn phíTruy cập →
06Nguồn cấp RSS và sản phẩm
RSS Feed Creator

Tạo RSS từ bất kỳ trang web nào, cùng nguồn cấp sản phẩm cho Google và Meta tự động cập nhật.

Gói miễn phíTruy cập →
07Phát triển website và SEO
Internet Solutions

Website, cửa hàng trực tuyến và hệ thống theo yêu cầu, do đội ngũ của chúng tôi thiết kế, xây dựng và vận hành.

Từ 2011Truy cập →
Site AI Audit
Tổng quan quyền riêng tư

Website này dùng cookie để mang lại trải nghiệm người dùng tốt nhất có thể. Thông tin cookie được lưu trong trình duyệt của bạn và thực hiện các chức năng như nhận ra bạn khi bạn quay lại, giúp đội ngũ chúng tôi hiểu phần nào của website bạn thấy thú vị và hữu ích nhất.