SSL Toolkit Logo

Certificate Transparency Search

Search Certificate Transparency logs for a domain

About Certificate Transparency

Certificate Transparency (CT) is a public logging system that records all TLS certificates issued by participating Certificate Authorities. By searching CT logs, you can discover every certificate that has been issued for your domain, monitor for unauthorized issuance, and maintain visibility into your certificate ecosystem. Our CT Search tool queries multiple CT log servers to provide a comprehensive view of a domain's certificate activity.

How to Use

  1. Enter the domain name you want to search for in CT logs.
  2. Click Check to query Certificate Transparency log servers.
  3. Browse the results to see all certificates issued for the domain, including issuer details and validity periods.
  4. Use the information to identify unexpected or potentially unauthorized certificate issuances.

Use Cases

  • Certificate Monitoring: Track all certificates issued for your domains to detect rogue or unauthorized certificates.
  • Security Incident Response: Investigate potential man-in-the-middle attacks by searching for suspicious certificates.
  • Inventory Management: Build a complete inventory of all certificates associated with your organization's domains.
  • Compliance Reporting: Verify that all certificates for your domains are properly logged in CT as required by browser policies.

Frequently Asked Questions

Certificate Transparency is an open framework for monitoring and auditing TLS certificates. All publicly trusted CAs must log every certificate they issue to CT logs, creating a public record that anyone can search and verify.
Searching CT logs helps you detect unauthorized certificate issuance, maintain an accurate certificate inventory, and ensure compliance with industry standards. If a certificate appears in CT logs that you didn't request, it could indicate a security breach.
Since April 2018, all publicly trusted TLS certificates must be logged in CT logs to be trusted by modern browsers. However, internally issued certificates from private CAs may not appear in public CT logs.

Tips & Best Practices

  • Search for wildcard certificates (*.yourdomain.com) to find subdomain certificates
  • Set up CT monitoring alerts for continuous protection instead of manual searches
  • Use date filters to focus on recent certificates during incident response
  • Combine CT search with DNS enumeration for complete domain discovery

Technical Details

Logs: All public CT logs including Google Argon, Cloudflare Nimbus, DigiCert Yeti
Data: Certificate details including issuer, validity, SAN entries, CT timestamps
Speed: Parallel queries across multiple CT logs
History: Data going back to CT log inception in 2013