What we checkReputationRP-05
Recent certificates
Every certificate issued for your domain is published. An unexpected one is worth knowing about.
- Area
- Reputation
- Check
- RP-05
- Included
- Free in every scan
What we check
We read certificate transparency logs for certificates issued for your domain in the last 90 days. Informational.
Why it matters
Every trusted CA must log what it issues, which means you can see certificates for your domain that you did not ask for.
An unexpected certificate can mean someone else controls a subdomain — often the same dangling subdomain DN-05 looks for, now with a valid certificate on it.
Certificate transparency is one of the few places where you can see something happening to your domain that you did not initiate — the logs are public, complete, and independent of whoever issued the certificate.
That makes an unfamiliar name here worth more attention than its severity suggests: it is evidence rather than inference.
How to fix it
- 1
Look at the names in each certificate and confirm you recognise them.
- 2
A CAA record limits who may issue in the first place.
Common questions
- Why do I have so many certificates?
- Short-lived certificates renew every 60 days, and a CDN may issue its own. A high count is normal; unfamiliar *names* are the signal.
- Someone issued a certificate for my subdomain.
- Check whether you still control that subdomain. If a service you left behind holds the name, this is a takeover in progress.
- Can I be notified about new certificates?
- Yes — several free CT monitoring services will email you. It is a good complement to this check.
See how your domain does on this check.
All 34 checks, a grade, and the exact fix for anything that isn’t right — in about twenty seconds, no signup.