Glossary

What is Certificate Transparency?

Certificate Transparency — public logs of every certificate issued, used to spot lookalikes and mis-issuance.

Written by the SkyQon engineering team · Last verified 4 August 2026

Why it matters

Every publicly trusted certificate must be recorded in public, append-only CT logs before browsers will accept it. That makes CT the one place where you can see certificates issued for your domain by anyone at all — including certificates nobody on your team requested.

The standard

RFC 6962 (2013), with version 2 specified in RFC 9162 (2021). Browsers require Signed Certificate Timestamps proving a certificate was submitted to independent logs, which are publicly queryable.

Official text: RFC 9162

How it fails

The logs themselves rarely go wrong; what goes wrong is that nobody looks at them. Mis-issuance, a forgotten department buying its own certificate, and lookalike domains being certified all appear in CT within minutes, then sit unnoticed for months. The real gap is between what your CA believes it issued and what is actually logged and serving traffic.

Related terms

Check this on your own domain

SkyQon reads the same public signals described on this page and scores them for your domain. No account, no agent, nothing to install — a scored report by email in minutes.