Compared: Cert Spotter
Cert Spotter vs. Attack Surface Scan
Both watch certificate transparency for certificates issued for your domains and check the certificate each host actually serves. Cert Spotter stops there, and goes deep. Attack Surface Scan treats the certificate as one part of the external attack surface, alongside headers, DNS, exposed ports, subdomain takeover and lookalike domains. This page is the honest version of that comparison, including where Cert Spotter is ahead.
No card required to start. Plans from $25/month. Cert Spotter facts checked September 2026.
The short version
Choose Cert Spotter if
Certificates are the whole job. You want installation checks every few minutes from several continents, revocation and OCSP stapling verification, and an API that lets your ACME pipeline pre-authorize keys before the CA sees them.
Choose Attack Surface Scan if
You want certificate monitoring inside a wider watch: security headers, exposed ports, takeover-prone subdomains, lookalike domains, and the weekly digest plus evidence pack that a small team or an MSP hands to a client or an auditor.
What is the same
Certificate transparency monitoring with an authorized-CA list and CAA awareness, an unknown-certificate queue, automatic subdomain discovery, custom ports with STARTTLS, per-domain expiry thresholds, MTA-STS checks, and alerts by email, Slack or webhook.
Feature by feature
Cert Spotter's column is from its public site, pricing page, help centre and changelog. Ours is from the product as it ships today, not the roadmap; roadmap items say so.
| Capability | Cert Spotter | Attack Surface Scan |
|---|---|---|
| Certificate transparency | ||
| Detection of a new certificate for your domain | Yes continuous ingestion of every browser-trusted log; alerts within minutes | Yes logs read every 15 minutes on every plan |
| Unknown vs. known certificates | Yes authorized CAs, CAA, pre-registered keys, manual acknowledgement | Yes authorized CAs, CAA, acknowledge once or acknowledge and trust the CA |
| Authorized CA list | Yes configured per account and per domain | Yes fills itself in from certificates your verified hosts actually serve; editable per org and per domain |
| Pre-authorize a CSR or public key before issuance | Yes Authorization API, recommended for ACME pipelines | No on the roadmap |
| Subdomain discovery | Yes every name seen in CT becomes a monitored endpoint | Yes names that resolve are added to monitoring automatically, with an exclusion list, plus dangling-CNAME takeover detection |
| Hardened certificate parsing | Yes catches names in malformed certificates and null-byte tricks | Yes we run SSLMate's open-source certspotter engine for CT ingestion, under its MPL licence, so the same parser |
| The certificate actually served | ||
| Check frequency | Yes hourly, every 15 minutes or every 5 minutes by plan | Partial daily on Starter, every 6 hours on Growth and above |
| Chain, hostname and key checks | Yes chain validation, hostname match | Yes chain trust, SAN coverage, key size, negotiated protocol, TLS 1.0/1.1 acceptance |
| Revocation and OCSP stapling | Yes | No not checked yet |
| Dual RSA and ECDSA certificates | Yes shows both when an endpoint serves both | No one handshake per endpoint |
| Custom ports and SMTP STARTTLS | Yes any port; Startup plan and above | Yes up to 10 extra ports per domain, STARTTLS on 25 and 587; every plan |
| Probing from several locations | Yes 10 locations on the Business plan | No one region |
| Stalled renewal detection | No | Yes a short-lived certificate still served past 70% of its lifetime raises an alert before expiry does |
| Unreachable endpoint alert | Yes monitoring-gap notification | Yes after 18 hours of failed checks |
| Expiry warning threshold | Yes account default, per-domain override | Yes per domain, then fixed steps at 14, 7, 3 and 1 days |
| Domain registration expiry (the domain itself) | No | Yes RDAP check with warnings at 60, 30, 14 and 7 days |
| Email domain posture | ||
| MTA-STS policy monitoring | Yes Email Domains view | Yes record, policy fetch, mode, MX coverage |
| SPF, DMARC and TLS-RPT | No | Yes |
| CAA record change alerts | Yes | Yes |
| Beyond certificates | ||
| HTTP security headers (HSTS, CSP, CORS, clickjacking) | No | Yes |
| Exposed services on common ports | No | Yes TCP connect on 14 ports, alerts when a sensitive port opens |
| Subdomain takeover (dangling CNAME) | No | Yes 10 provider fingerprints |
| Lookalike and typosquat domains | No | Yes Growth and above |
| Technology fingerprint changes | No | Yes |
| PDF reports and compliance evidence pack | No | Yes SOC 2 CC7.1 and ISO 27001 A.8.8 cadence evidence |
| Client workspaces and white-label reports | No | Yes MSP plan |
| Notifications, API and account | ||
| Email, Slack and webhook alerts | Yes webhooks on Startup and above | Yes every plan; confirmed recipients, HTTPS-only webhooks |
| Weekly digest | Partial daily expiring-certificate summary | Yes what changed this week, grouped by domain, suppressed findings left out |
| REST API with API keys | Yes Monitored Domains and Authorization APIs | No REST is session-authenticated today; API keys are on the roadmap |
| AI agent access (MCP) | No | Yes hosted MCP server with OAuth 2.1; run scans, read findings, acknowledge certificates from Claude or Cursor |
| DNS provider and registrar integrations | Yes Cloudflare, Route 53, Azure DNS and others, for approval records and discovery | No ownership is proven with one TXT record, a file on the site, or your work email |
| Team seats | Yes multiple address routing on Startup and above | Yes roles and invites on every plan; 2 to 25 seats by plan |
| Audit log | Yes 30, 90 or unlimited days by plan | No change feed only; account audit log is on the roadmap |
Where Cert Spotter is ahead
Said plainly, because a comparison that only lists wins is an advert.
Faster installation checks
Every 15 minutes on Startup and every 5 minutes on Business, against our daily and 6-hourly probes. If a misdeployed certificate needs to be caught inside a quarter hour, that gap matters.
Ten probing locations
Business-plan endpoints are checked from every continent but Antarctica, which catches a regional CDN edge serving a stale certificate. We probe from one region.
Revocation, stapling, dual certificates
Cert Spotter verifies OCSP stapling, detects revoked certificates, and shows both leaves when a host serves RSA and ECDSA. We check chain, hostname, key size and protocol, and stop there for now.
API keys and pre-authorization
A REST API with an account key, plus an Authorization API that accepts a CSR before issuance so the resulting certificate never alerts. Our API surface today is the MCP server; API keys and CSR pre-authorization are on the roadmap.
Where Attack Surface Scan goes further
The rest of the attack surface
HTTP security headers, CORS, exposed database and admin ports, technology fingerprint drift, dangling-CNAME subdomain takeover and lookalike domain registrations, all diffed scan to scan and alerted on. Cert Spotter has no equivalent for any of it.
Stalled renewal, before it is an outage
A 90-day certificate that is still being served at 70% of its lifetime has almost certainly outlived its renewal job. We say so weeks before the expiry warning would, which is the failure that actually takes sites down.
Reports someone can hand over
Branded PDF reports per scan and a compliance evidence pack showing scan cadence and coverage over time, for SOC 2 CC7.1 and ISO 27001 A.8.8. MSPs get client workspaces and per-client alert routing under their own brand.
An authorized-CA list that writes itself
A certificate served with a valid chain on a host you have verified is one you deployed, so its CA is authorized. The list fills in from your first scan and you only ever trim it. Domain registration expiry is watched too, via RDAP.
Every Attack Surface Scan check is passive and runs only against domains whose owner has proven control: a DNS TXT token, a file on the site, or a verified mailbox at the domain. Nothing is installed; nothing is scanned without proof of control.
Pricing side by side
Cert Spotter prices per endpoint. Attack Surface Scan prices per domain, with hosts included. Both offer annual billing; Cert Spotter's trial is 30 days, ours is 7 days with no card.
| Cert Spotter | Monthly | Covers | Install checks |
|---|---|---|---|
| Hobbyist | $15 | 20 endpoints | hourly |
| Startup | $100 | 150 endpoints | every 15 minutes |
| Business | $500 | 1,000 endpoints | every 5 minutes, 10 locations |
| Attack Surface Scan | Monthly | Covers | Certificate checks |
|---|---|---|---|
| Starter | $25 | 1 domain, 20 hosts each, full external scan weekly | daily, CT every 15 minutes |
| Growth | $49 | 5 domains, 100 hosts each, full external scan daily | every 6 hours, CT every 15 minutes |
| MSP | $149 | 25 domains, 250 hosts each, full external scan daily | every 6 hours, CT every 15 minutes |
Cert Spotter prices from sslmate.com/certspotter/pricing, checked September 2026. Ours are generated from the same plan catalog checkout uses, so they cannot drift.
Questions people ask
Is this page fair to Cert Spotter?
That is the intent. Cert Spotter is a good product and a narrower one: it does certificate transparency and installed-certificate monitoring, deeply, and nothing else. Every row above where it is ahead is marked as such. Facts about Cert Spotter come from sslmate.com and were last checked in September 2026. If something is wrong or out of date, tell us and it will be corrected.
Do you read certificate transparency logs yourselves?
Yes, using SSLMate's open-source certspotter daemon as the ingestion engine, run
on our own infrastructure under its Mozilla Public License. It follows every log in the
Chrome and Apple log lists. We run it every 15 minutes rather than continuously, which is
why our detection latency is "within the quarter hour" and theirs is "within minutes".
Can I use both?
Certainly. Some teams keep Cert Spotter for its 5-minute installation checks and multi-location probing and use Attack Surface Scan for everything around the certificate: headers, exposed ports, subdomain takeover, lookalike domains, and the evidence pack an auditor asks for. Both send to Slack and webhooks, so they can land in the same channel.
How does pricing compare?
Cert Spotter charges per endpoint. Attack Surface Scan charges per registrable domain, with a number of hosts included per domain (20 on Starter, 100 on Growth, 250 on MSP). A small estate with one domain and a dozen hosts pays $25 here against $15 there, and gets the full external scan for the difference. A larger estate with five domains and a hundred hosts pays $49 here against $100 there.
What does Cert Spotter do that you do not?
Installation checks every 5 to 15 minutes on its upper tiers, probing from ten locations, revocation and OCSP stapling checks, dual RSA/ECDSA detection, an API-key REST API with CSR pre-authorization, DNS provider integrations, and an account audit log. Several of these are on our roadmap; the multi-location probing is not.
See the whole surface, certificates included.
Verify a domain and get the full external picture, with certificate transparency watching from the first quarter hour.
Start your 7-day trialNo card required to start. Cancel any time.