Certificates
Certificate Transparency Watch
Every certificate authority must write the certificates it issues into a public log. That means certificates issued in your name are something you can watch. When a domain is hijacked, the attacker's first move is usually to get their own certificate — and you see that entry the moment it lands.
Checked hourly
Certificate Transparency logs are scanned every hour. Every new certificate issued for your name is reported, along with who issued it.
Expected and unexpected are separated
Your own auto-renewals create no noise. A certificate from an authority you don't use is a separate, higher-priority alert.
It feeds asset discovery too
Certificate records also give away subdomains you didn't know about. Every new name found here joins your asset inventory.
specula.com.tr
Let's Encrypt · 12 Jul
app.specula.com.tr
Let's Encrypt · 12 Jul
mail.specula.com.tr
Unknown CA · yesterday
1 unexpected certificate · yesterday 04:12 · awaiting review
Other features
Run this check on your own domain.
Add a domain and Specula finishes the first scan within minutes. No credit card needed.