Monitor SSL certificate issuance and detect unauthorized certificates.
Certificate Transparency Monitoring
Certificate Transparency (CT) logs are a public record of every SSL certificate issued for your domain. LemWatch monitors these logs to detect unauthorized certificate issuance.
Why It Matters
Detect unauthorized certificates — If someone obtains a certificate for your domain without your knowledge, it could indicate a security breach or phishing attempt
Subdomain discovery — CT logs reveal all subdomains that have certificates, including ones you might have forgotten about
Issuer tracking — See which Certificate Authorities (CAs) have issued certificates for your domain
What You'll See
Total certificates found — How many certificates exist for your domain in CT logs
Certificate issuers — Which CAs issued the certificates (Let's Encrypt, Cloudflare, DigiCert, etc.)
Subdomains discovered — All subdomains with certificates
Expired certificates — Certificates that have passed their validity period
New certificates since last check — Alerts on newly issued certificates
Alerts
LemWatch alerts you when:
A new certificate is issued for your domain by an unexpected CA
A certificate is issued for a subdomain you don't recognise
The total number of certificates changes unexpectedly
Limitations
CT log monitoring is passive — it detects certificates after they're issued, not before. For proactive protection, combine with CAA DNS records that restrict which CAs can issue certificates for your domain.