What does this mean for you? Imagine an attacker, perhaps by briefly controlling your DNS settings, or even a former vendor whose access was never revoked, or a phishing operator setting up a fake login page under your brand's domain, gets a real, publicly trusted TLS/SSL certificate for a name under your domain. This certificate would be perfectly valid, and browsers would trust it. The big problem here is that your usual monitoring tools won't catch this. Why? Because this unauthorized certificate would never be served on your actual servers. Your website's uptime checks would look normal, and your real certificate's expiry monitoring wouldn't flag any issues. All your dashboards would stay green, while a certificate you never ordered exists out in the world with your name on it.
The good news is there's one guaranteed place this certificate will appear: the Certificate Transparency logs—a system most teams don't watch at all. Monitoring these logs is the difference between finding out about a problem yourself or hearing it from a customer who fell victim to a phishing scam.
Certificate Transparency logs are public, append-only, cryptographically-verifiable records of all issued certificates. When a Certificate Authority (CA) issues a certificate, it must submit it to these independent logs. Since 2018, major browsers like Chrome and Safari refuse to trust any publicly trusted certificate unless it carries valid Signed Certificate Timestamps (SCTs) proving it was publicly logged. This means that any certificate that works in browsers is, by design, a certificate that is written down somewhere you can read. You can't watch every CA, every DNS provider, or every corner of your own shadow IT. But you don't have to. Every valid certificate for your domain has to announce itself in public, whether you ordered it or not. So, start watching CT logs today to protect your domain!