Guides · Understand your certificate

Certificate Transparency: why names you did not expect show up for your domain

Last reviewed by a person on October 4, 2026

Search for your own domain in a Certificate Transparency log and you may find names you forgot, or never knew about: staging.example.com, old-shop.example.com, vpn.example.com. Nothing is leaking and nobody is hacking you: that is how the system is designed. This guide explains what it is and what to do with what you find.

What Certificate Transparency is

Certificate authorities (CAs) used to issue certificates without leaving any public trace, so a mistaken or malicious certificate for a name could exist for years unnoticed. Certificate Transparency (CT) fixes that: publicly trusted CAs write the TLS certificates they issue to public, append-only logs that anyone can read. Browsers such as Chrome and Safari require it for the certificates they trust, so in practice a certificate from a public CA is logged, usually as it is issued.

What this means for your domain

  • Publicly logged certificates for your domain are generally discoverable, including for subdomains you never advertised. Search tools such as crt.sh list them by domain.
  • That is good for you. You (and domain owners everywhere) can spot a certificate you did not request, and a CA that issued one wrongly can be caught.
  • It also tells the world your hostnames. An internal name that got a public certificate is visible. For names that must stay private, use an internal CA, whose certificates aren't logged. A wildcard only keeps the name off that one certificate: DNS, other certificates and other sources can still reveal it, so don't rely on a hostname staying secret.

Why unknown names appear

  • You or a colleague created them. Test and staging sites, an old marketing campaign, a one-off tool, a vendor's setup. Often forgotten, but still alive.
  • A service created them for you. Hosting panels, website builders, CDNs and email platforms request certificates for subdomains when you connect them.
  • Someone obtained one who should not have. Rare, and the logs are exactly how you would find out. A CAA record narrows who can issue; see CAA records explained.

Look-alike domains (examp1e.com) are different domains and will not show up under yours.

What to do with each name you find

  1. It is yours and still used: monitor it. A forgotten staging site still has a certificate that will expire, and the day a customer is sent there you want to know it is healthy.
  2. It is yours and no longer needed: shut it down, and delete its DNS record too. A DNS record that points at a deleted service can let someone else claim that service and serve content on your subdomain (a "subdomain takeover").
  3. You are not sure: find out who created it before you delete it. The certificate's issue date and the CA that issued it are clues.
  4. You can't explain it: investigate. It may be a vendor, agency or service acting for you, or something forgotten, so ask around first (the issuing CA is a clue). If nobody requested it, check your DNS for unexpected records, review who has access to your registrar and DNS accounts, and consider restricting issuance with CAA.

How CertAvert uses it

On each domain's Other names tab, CertAvert looks the domain up in the public logs (through crt.sh, or Cert Spotter when crt.sh does not answer) and lists the names under it that have a current certificate and still resolve in DNS today. Names you already monitor or that are on one of your certificates are left out. For each one you can add it to monitor, acknowledge it ("I know about this") or leave a note. We send only the domain name to those services, and a lookup repeats about once a day. The free SSL checker shows how many other names exist, but not their names. Sign-in is needed to see them. Monitor a domain with CertAvert to see what is under yours.

Related: SAN and wildcard certificates.

Don't wait for the browser warning

Check any site's certificate in a few seconds with the SSL/TLS checker, or sign up free and CertAvert emails you before certificates expire.

Understand your certificate: more guides

All guides