What is Certificate Transparency?
Certificate Transparency — public logs of every certificate issued, used to spot lookalikes and mis-issuance.
Written by the SkyQon engineering team · Last verified 4 August 2026
Why it matters
Every publicly trusted certificate must be recorded in public, append-only CT logs before browsers will accept it. That makes CT the one place where you can see certificates issued for your domain by anyone at all — including certificates nobody on your team requested.
The standard
RFC 6962 (2013), with version 2 specified in RFC 9162 (2021). Browsers require Signed Certificate Timestamps proving a certificate was submitted to independent logs, which are publicly queryable.
Official text: RFC 9162
How it fails
The logs themselves rarely go wrong; what goes wrong is that nobody looks at them. Mis-issuance, a forgotten department buying its own certificate, and lookalike domains being certified all appear in CT within minutes, then sit unnoticed for months. The real gap is between what your CA believes it issued and what is actually logged and serving traffic.
Related terms
Check this on your own domain
SkyQon reads the same public signals described on this page and scores them for your domain. No account, no agent, nothing to install — a scored report by email in minutes.