Certificate transparency watch
Every certificate anyone issues for your domain, watched in the public logs before you'd otherwise hear about it.
Included on Pro and Business.
| What breaks | hostnag |
|---|---|
| Someone issues a certificate for your domainnew certificates in the transparency logs, daily | Yes |
How it works
- 01
Add the domain
hostnag watches it and, by default, its subdomains too.
- 02
hostnag polls crt.sh once a day
The interval is fixed at daily on every plan; crt.sh is a shared, rate-limited service.
- 03
Say which issuers you expect
An optional list of expected certificate authorities; anything outside it is marked unexpected the moment it appears.
- 04
One alert per new certificate
Never a digest: each new certificate in the logs raises its own Changed event with the issuer and the names it covers.
What you'll be told
What you get told
- CT
[Warning] New certificate for example.com
Seen in certificate transparency logs: ZeroSSL RSA Domain Secure Site CA for example.com, www.example.com, issued 10 Sept 2026. Expected: no. If you did not order this, check who has access to your DNS and your CA account.
Sample alerts, rendered by the same code that writes your email and Slack messages.
Settings
- Target
- a domain, subdomains included by default
- Interval
- daily, fixed on every plan
- Expected issuers
- an optional allowlist
- Plans
- Pro and Business
Questions
Why can't I poll more often than once a day?
crt.sh is a shared, rate-limited service; hostnag polls it the same way on every plan.
Does it see certificates hostnag itself hasn't reached yet?
Yes. The transparency logs list every certificate a public authority issues, whether or not it's live on a host yet.
Related
Add a host. Hear about it first.
Start free