Compared: Cert Spotter

Cert Spotter vs. Attack Surface Scan

Both watch certificate transparency for certificates issued for your domains and check the certificate each host actually serves. Cert Spotter stops there, and goes deep. Attack Surface Scan treats the certificate as one part of the external attack surface, alongside headers, DNS, exposed ports, subdomain takeover and lookalike domains. This page is the honest version of that comparison, including where Cert Spotter is ahead.

No card required to start. Plans from $25/month. Cert Spotter facts checked September 2026.

The short version

Choose Cert Spotter if

Certificates are the whole job. You want installation checks every few minutes from several continents, revocation and OCSP stapling verification, and an API that lets your ACME pipeline pre-authorize keys before the CA sees them.

Choose Attack Surface Scan if

You want certificate monitoring inside a wider watch: security headers, exposed ports, takeover-prone subdomains, lookalike domains, and the weekly digest plus evidence pack that a small team or an MSP hands to a client or an auditor.

What is the same

Certificate transparency monitoring with an authorized-CA list and CAA awareness, an unknown-certificate queue, automatic subdomain discovery, custom ports with STARTTLS, per-domain expiry thresholds, MTA-STS checks, and alerts by email, Slack or webhook.

Feature by feature

Cert Spotter's column is from its public site, pricing page, help centre and changelog. Ours is from the product as it ships today, not the roadmap; roadmap items say so.

CapabilityCert SpotterAttack Surface Scan
Certificate transparency
Detection of a new certificate for your domain Yes continuous ingestion of every browser-trusted log; alerts within minutes Yes logs read every 15 minutes on every plan
Unknown vs. known certificates Yes authorized CAs, CAA, pre-registered keys, manual acknowledgement Yes authorized CAs, CAA, acknowledge once or acknowledge and trust the CA
Authorized CA list Yes configured per account and per domain Yes fills itself in from certificates your verified hosts actually serve; editable per org and per domain
Pre-authorize a CSR or public key before issuance Yes Authorization API, recommended for ACME pipelines No on the roadmap
Subdomain discovery Yes every name seen in CT becomes a monitored endpoint Yes names that resolve are added to monitoring automatically, with an exclusion list, plus dangling-CNAME takeover detection
Hardened certificate parsing Yes catches names in malformed certificates and null-byte tricks Yes we run SSLMate's open-source certspotter engine for CT ingestion, under its MPL licence, so the same parser
The certificate actually served
Check frequency Yes hourly, every 15 minutes or every 5 minutes by plan Partial daily on Starter, every 6 hours on Growth and above
Chain, hostname and key checks Yes chain validation, hostname match Yes chain trust, SAN coverage, key size, negotiated protocol, TLS 1.0/1.1 acceptance
Revocation and OCSP stapling Yes No not checked yet
Dual RSA and ECDSA certificates Yes shows both when an endpoint serves both No one handshake per endpoint
Custom ports and SMTP STARTTLS Yes any port; Startup plan and above Yes up to 10 extra ports per domain, STARTTLS on 25 and 587; every plan
Probing from several locations Yes 10 locations on the Business plan No one region
Stalled renewal detection No Yes a short-lived certificate still served past 70% of its lifetime raises an alert before expiry does
Unreachable endpoint alert Yes monitoring-gap notification Yes after 18 hours of failed checks
Expiry warning threshold Yes account default, per-domain override Yes per domain, then fixed steps at 14, 7, 3 and 1 days
Domain registration expiry (the domain itself) No Yes RDAP check with warnings at 60, 30, 14 and 7 days
Email domain posture
MTA-STS policy monitoring Yes Email Domains view Yes record, policy fetch, mode, MX coverage
SPF, DMARC and TLS-RPT No Yes
CAA record change alerts Yes Yes
Beyond certificates
HTTP security headers (HSTS, CSP, CORS, clickjacking) No Yes
Exposed services on common ports No Yes TCP connect on 14 ports, alerts when a sensitive port opens
Subdomain takeover (dangling CNAME) No Yes 10 provider fingerprints
Lookalike and typosquat domains No Yes Growth and above
Technology fingerprint changes No Yes
PDF reports and compliance evidence pack No Yes SOC 2 CC7.1 and ISO 27001 A.8.8 cadence evidence
Client workspaces and white-label reports No Yes MSP plan
Notifications, API and account
Email, Slack and webhook alerts Yes webhooks on Startup and above Yes every plan; confirmed recipients, HTTPS-only webhooks
Weekly digest Partial daily expiring-certificate summary Yes what changed this week, grouped by domain, suppressed findings left out
REST API with API keys Yes Monitored Domains and Authorization APIs No REST is session-authenticated today; API keys are on the roadmap
AI agent access (MCP) No Yes hosted MCP server with OAuth 2.1; run scans, read findings, acknowledge certificates from Claude or Cursor
DNS provider and registrar integrations Yes Cloudflare, Route 53, Azure DNS and others, for approval records and discovery No ownership is proven with one TXT record, a file on the site, or your work email
Team seats Yes multiple address routing on Startup and above Yes roles and invites on every plan; 2 to 25 seats by plan
Audit log Yes 30, 90 or unlimited days by plan No change feed only; account audit log is on the roadmap

Where Cert Spotter is ahead

Said plainly, because a comparison that only lists wins is an advert.

Faster installation checks

Every 15 minutes on Startup and every 5 minutes on Business, against our daily and 6-hourly probes. If a misdeployed certificate needs to be caught inside a quarter hour, that gap matters.

Ten probing locations

Business-plan endpoints are checked from every continent but Antarctica, which catches a regional CDN edge serving a stale certificate. We probe from one region.

Revocation, stapling, dual certificates

Cert Spotter verifies OCSP stapling, detects revoked certificates, and shows both leaves when a host serves RSA and ECDSA. We check chain, hostname, key size and protocol, and stop there for now.

API keys and pre-authorization

A REST API with an account key, plus an Authorization API that accepts a CSR before issuance so the resulting certificate never alerts. Our API surface today is the MCP server; API keys and CSR pre-authorization are on the roadmap.

Where Attack Surface Scan goes further

The rest of the attack surface

HTTP security headers, CORS, exposed database and admin ports, technology fingerprint drift, dangling-CNAME subdomain takeover and lookalike domain registrations, all diffed scan to scan and alerted on. Cert Spotter has no equivalent for any of it.

Stalled renewal, before it is an outage

A 90-day certificate that is still being served at 70% of its lifetime has almost certainly outlived its renewal job. We say so weeks before the expiry warning would, which is the failure that actually takes sites down.

Reports someone can hand over

Branded PDF reports per scan and a compliance evidence pack showing scan cadence and coverage over time, for SOC 2 CC7.1 and ISO 27001 A.8.8. MSPs get client workspaces and per-client alert routing under their own brand.

An authorized-CA list that writes itself

A certificate served with a valid chain on a host you have verified is one you deployed, so its CA is authorized. The list fills in from your first scan and you only ever trim it. Domain registration expiry is watched too, via RDAP.

Every Attack Surface Scan check is passive and runs only against domains whose owner has proven control: a DNS TXT token, a file on the site, or a verified mailbox at the domain. Nothing is installed; nothing is scanned without proof of control.

Pricing side by side

Cert Spotter prices per endpoint. Attack Surface Scan prices per domain, with hosts included. Both offer annual billing; Cert Spotter's trial is 30 days, ours is 7 days with no card.

Cert SpotterMonthlyCoversInstall checks
Hobbyist$1520 endpointshourly
Startup$100150 endpointsevery 15 minutes
Business$5001,000 endpointsevery 5 minutes, 10 locations
Attack Surface ScanMonthlyCoversCertificate checks
Starter $25 1 domain, 20 hosts each, full external scan weekly daily, CT every 15 minutes
Growth $49 5 domains, 100 hosts each, full external scan daily every 6 hours, CT every 15 minutes
MSP $149 25 domains, 250 hosts each, full external scan daily every 6 hours, CT every 15 minutes

Cert Spotter prices from sslmate.com/certspotter/pricing, checked September 2026. Ours are generated from the same plan catalog checkout uses, so they cannot drift.

Questions people ask

Is this page fair to Cert Spotter?

That is the intent. Cert Spotter is a good product and a narrower one: it does certificate transparency and installed-certificate monitoring, deeply, and nothing else. Every row above where it is ahead is marked as such. Facts about Cert Spotter come from sslmate.com and were last checked in September 2026. If something is wrong or out of date, tell us and it will be corrected.

Do you read certificate transparency logs yourselves?

Yes, using SSLMate's open-source certspotter daemon as the ingestion engine, run on our own infrastructure under its Mozilla Public License. It follows every log in the Chrome and Apple log lists. We run it every 15 minutes rather than continuously, which is why our detection latency is "within the quarter hour" and theirs is "within minutes".

Can I use both?

Certainly. Some teams keep Cert Spotter for its 5-minute installation checks and multi-location probing and use Attack Surface Scan for everything around the certificate: headers, exposed ports, subdomain takeover, lookalike domains, and the evidence pack an auditor asks for. Both send to Slack and webhooks, so they can land in the same channel.

How does pricing compare?

Cert Spotter charges per endpoint. Attack Surface Scan charges per registrable domain, with a number of hosts included per domain (20 on Starter, 100 on Growth, 250 on MSP). A small estate with one domain and a dozen hosts pays $25 here against $15 there, and gets the full external scan for the difference. A larger estate with five domains and a hundred hosts pays $49 here against $100 there.

What does Cert Spotter do that you do not?

Installation checks every 5 to 15 minutes on its upper tiers, probing from ten locations, revocation and OCSP stapling checks, dual RSA/ECDSA detection, an API-key REST API with CSR pre-authorization, DNS provider integrations, and an account audit log. Several of these are on our roadmap; the multi-location probing is not.

See the whole surface, certificates included.

Verify a domain and get the full external picture, with certificate transparency watching from the first quarter hour.

Start your 7-day trial

No card required to start. Cancel any time.