Certificate transparency, every 15 minutes

We run SSLMate's open-source certspotter engine (MPL-2.0) against every log in the Chrome and Apple log lists, every 15 minutes, on every plan. A certificate issued for any verified domain shows up within the quarter hour. New names in it are added to monitoring.

A nightly sweep of crt.sh is kept as a slower backstop.

Authorized CAs and the unknown-certificate queue

An issuance is known when its CA is on your organisation's authorized list, on the domain's own list, or permitted by the domain's CAA records (optional per domain). The org list fills itself in: a certificate served with a valid chain on a verified host is one you deployed, so its CA is authorized.

Anything else goes to the unknown-certificate queue and raises a critical change at once: this is what mis-issuance and staged phishing infrastructure look like. From the queue you can acknowledge a certificate, or acknowledge it and trust its CA from then on.

Served-certificate probes

Separately from full scans, one TLS handshake per endpoint checks the certificate each host is serving: daily on Starter, every 6 hours on Growth and above. Changes it reports:

  • Expiry warnings at your first threshold (30 days by default), then 14, 7, 3 and 1 days.
  • Renewals and issuer changes.
  • Stalled renewal: a short-lived certificate still served past about 70% of its lifetime. This fires weeks before the expiry warning would, and it is the failure that actually takes sites down.
  • An endpoint that has failed every probe for 18 hours.

Extra ports and STARTTLS

Add up to 10 extra ports per domain in its settings (mail servers, admin consoles, APIs on non-standard ports). They are probed on the apex and saved subdomains, with SMTP STARTTLS on 25 and 587, and each port's findings carry the port in their ID (tls.cert-expiring@8443).

Checks

Per-domain settings

First expiry-warning threshold, unknown-CA alerts on or off, served-certificate monitoring on or off, CAA honouring, per-domain authorized CAs and extra TLS ports.