Certificate transparency, every 15 minutes
We run SSLMate's open-source certspotter engine (MPL-2.0) against every log in the
Chrome and Apple log lists, every 15 minutes, on every plan. A certificate issued for any verified
domain shows up within the quarter hour. New names in it are added to monitoring.
A nightly sweep of crt.sh is kept as a slower backstop.
Authorized CAs and the unknown-certificate queue
An issuance is known when its CA is on your organisation's authorized list, on the domain's own list, or permitted by the domain's CAA records (optional per domain). The org list fills itself in: a certificate served with a valid chain on a verified host is one you deployed, so its CA is authorized.
Anything else goes to the unknown-certificate queue and raises a critical change at once: this is what mis-issuance and staged phishing infrastructure look like. From the queue you can acknowledge a certificate, or acknowledge it and trust its CA from then on.
Served-certificate probes
Separately from full scans, one TLS handshake per endpoint checks the certificate each host is serving: daily on Starter, every 6 hours on Growth and above. Changes it reports:
- Expiry warnings at your first threshold (30 days by default), then 14, 7, 3 and 1 days.
- Renewals and issuer changes.
- Stalled renewal: a short-lived certificate still served past about 70% of its lifetime. This fires weeks before the expiry warning would, and it is the failure that actually takes sites down.
- An endpoint that has failed every probe for 18 hours.
Extra ports and STARTTLS
Add up to 10 extra ports per domain in its settings (mail servers, admin consoles, APIs on
non-standard ports). They are probed on the apex and saved subdomains, with SMTP STARTTLS on 25 and
587, and each port's findings carry the port in their ID (tls.cert-expiring@8443).
Checks
tls.cert-expiredcritical Certificate is expiredtls.cert-expiringhigh Certificate expires soontls.cert-expiring-soonlow Certificate expiry approachingtls.renewal-stalledmedium Certificate renewal looks stalledtls.untrusted-certhigh Certificate did not validatetls.hostname-mismatchhigh Certificate does not cover the hostnametls.weak-negotiated-protocolhigh Weak protocol negotiatedtls.tls10-enabledmedium TLS 1.0 is acceptedtls.tls11-enabledmedium TLS 1.1 is acceptedtls.weak-keyhigh Weak certificate keytls.weak-signaturemedium Certificate signed with a weak algorithmtls.<check>@<port>varies Certificate checks on extra portstls.port-unreachable@<port>low TLS on an extra port could not be checked
Per-domain settings
First expiry-warning threshold, unknown-CA alerts on or off, served-certificate monitoring on or off, CAA honouring, per-domain authorized CAs and extra TLS ports.