TLS · Email & certs

TLS certificates: how Certificate Transparency works

Published 2026-10-05

When a certificate authority (CA) issues a TLS certificate for your domain, it must log the certificate to a public append-only database called a Certificate Transparency (CT) log. Browsers require CT-signed SCTs (signed certificate timestamps) for any certificate that handles HTTPS. The CT logs are searchable, which is why /cert-checker/ can show you the full certificate history for any domain.

TL;DR

Every TLS certificate issued for your domain is logged publicly. The CT logs let you see who issued what, when, and for which names. Here is how to use them.

What a CT log contains

For each certificate issued by a trusted CA, the CT log stores: the domain (or wildcard), the issuing CA, the validity period (Not Before / Not After), the Subject Alternative Names (SAN list), the public key fingerprint, and a serial number. The log is append-only — certificates are added but never removed. Anyone can query any CA's logs through a public API.

Why CT was created

Before CT, a malicious or compromised CA could issue a certificate for any domain without the domain owner knowing. There was no public record of which certificates existed. CT fixes this by making issuance public — if a CA issues a certificate for your domain that you did not request, you will see it in the logs within minutes. Several CAs have been caught this way.

How to use the CT logs

To check what certificates have been issued for a domain, query the CT logs (crt.sh, Google's pilot CT log, Facebook's CT log). The result is the full issuance history: which CAs issued which certificates, when, for which subdomains. /cert-checker/ queries these logs and renders the result as a sortable table. If you see a certificate you did not request, contact the issuing CA to revoke it.

CT and browser trust

Modern browsers (Chrome, Firefox, Safari, Edge) require CT-signed SCTs in TLS handshakes. If a certificate has no CT log entry, the browser refuses the connection. This is a hard requirement, not a soft one — the certificate is technically valid but operationally useless. CT is therefore a load-bearing part of the modern TLS ecosystem.

Try it →

Run the Certificate checker tool on sitetrace.it.com — paste a value and get an instant answer.

Open Certificate checker