Certificate transparency watch

Every certificate anyone issues for your domain, watched in the public logs before you'd otherwise hear about it.

Included on Pro and Business.

PlansFreeProBusiness
What Certificate transparency watch catches
What breakshostnag
Someone issues a certificate for your domainYes

How it works

  1. 01

    Add the domain

    hostnag watches it and, by default, its subdomains too.

  2. 02

    hostnag polls crt.sh once a day

    The interval is fixed at daily on every plan; crt.sh is a shared, rate-limited service.

  3. 03

    Say which issuers you expect

    An optional list of expected certificate authorities; anything outside it is marked unexpected the moment it appears.

  4. 04

    One alert per new certificate

    Never a digest: each new certificate in the logs raises its own Changed event with the issuer and the names it covers.

What you'll be told

What you get told

  1. [Warning] New certificate for example.com

    Seen in certificate transparency logs: ZeroSSL RSA Domain Secure Site CA for example.com, www.example.com, issued 10 Sept 2026. Expected: no. If you did not order this, check who has access to your DNS and your CA account.

    CT

Sample alerts, rendered by the same code that writes your email and Slack messages.

Settings

Target
a domain, subdomains included by default
Interval
daily, fixed on every plan
Expected issuers
an optional allowlist
Plans
Pro and Business

Questions

Why can't I poll more often than once a day?

crt.sh is a shared, rate-limited service; hostnag polls it the same way on every plan.

Does it see certificates hostnag itself hasn't reached yet?

Yes. The transparency logs list every certificate a public authority issues, whether or not it's live on a host yet.

Related

Add a host. Hear about it first.

Start free