</> Web Validators

Certificate Transparency Checker

Public CT log history for certificates issued to this domain.

This is one independent signal used by the Domain Security Score, and can also be run on its own for any domain.

Based on: RFC 6962 — Certificate Transparency

About this validation

Public CT log history for certificates issued to a domain.

Rules reviewed:
Sep 6, 2026

SEOTechTests methodology: Data source: a live query of public Certificate Transparency logs for certificates issued to this domain. Standard: RFC 6962 defines the CT log format actually deployed and used by browsers/logs today -- its formal successor, RFC 9162 (CT v2.0), exists but isn't deployed, so RFC 6962 reflects what's actually running in production.

Standards and vendor-documented behavior can change. This reflects the source as last reviewed above, not a permanent guarantee.

FAQ

What is Certificate Transparency?

A public, append-only log system where Certificate Authorities record every TLS certificate they issue, letting anyone (including a domain owner) audit which certificates have been issued for a domain.

Why check CT logs for a domain?

It can reveal a certificate issued for the domain that the domain owner didn't request -- a strong signal of a compromised or misused CA account, or of a subdomain the owner may not be aware of.

Does a domain with no unusual CT entries guarantee no mis-issuance ever happened?

No -- it only covers logs this check queries and the visibility window available; a very recent or unusual issuance can take time to appear.

Why does this check reference RFC 6962 rather than the newer RFC 9162?

RFC 9162 (Certificate Transparency v2.0) is technically the current IETF specification, but no CT logs or major browsers have adopted it -- every log and consumer in production today, including the ones this check queries, implements RFC 6962.