OFICIAL Cloudflare Blog

Certificate Transparency Monitoring is now generally available

What happened
Based on Cloudflare Blog · Aug 13, 2026

Cloudflare has made Certificate Transparency Monitoring generally available after addressing noise from its own certificate renewals. The service now filters out Cloudflare-issued certificates to reduce unnecessary alerts.

Certificate Transparency Monitoring is now generally available
Cloudflare Blog — Cloudflare
Key points
·
Since we launched Certificate Transparency Monitoring in public beta in 2019, we've been emailing subscribers whenever a new TLS certificate appears in a public Certificate Transparency (CT) log for one of their domains.
·
Today, it's turned on for more than 650,000 customer domains.
·
It's an early warning that someone, somewhere, has issued a certificate for a hostname in your zone, giving you a chance to spot a mis-issued certificate early.
·
It's a useful signal, but it had a noise problem, and we felt it ourselves.
Key numbers
·
Initially launched in public beta in 2019, the service now monitors over 650,000 customer domains.
·
Since certificates renew frequently—sometimes every 60 days—and browsers require logging for trust, these renewals generated repetitive alerts.
·
The company determined that the public key, specifically its SHA-256 hash (spki_sha256), could uniquely link certificates to Cloudflare's issuance process.

Cloudflare announced the general availability of Certificate Transparency Monitoring, a service that alerts customers when a new TLS certificate appears in public logs for their domains. Initially launched in public beta in 2019, the service now monitors over 650,000 customer domains. It serves as an early warning system for potentially mis-issued certificates, though it previously generated excessive alerts due to Cloudflare's own routine renewals. Customers reported being overwhelmed by notifications for normal certificate renewals, prompting the company to address the issue.

The previous system flagged every certificate logged in public Certificate Transparency logs, including those issued by Cloudflare for services like Universal SSL and Advanced Certificate Manager. Since certificates renew frequently—sometimes every 60 days—and browsers require logging for trust, these renewals generated repetitive alerts. Cloudflare's internal systems and the Certificate Transparency alerting service operated independently, creating a gap that led to duplicate or irrelevant notifications. Customers described the volume of alerts as disruptive, with one noting they had disabled the feature entirely due to the noise.

To resolve this, Cloudflare implemented a filtering mechanism that excludes certificates it issued from alert emails. The solution involved identifying a persistent identifier shared between Cloudflare's certificate ordering system and the public Certificate Transparency logs. The company determined that the public key, specifically its SHA-256 hash (spki_sha256), could uniquely link certificates to Cloudflare's issuance process. This identifier is recorded early in the certificate ordering flow and used by the alerting service to verify whether a logged certificate was issued internally.

The updated system now ensures alerts are sent only for certificates issued outside Cloudflare's automated processes. Notifications include the affected hostname, certificate details, and a link to the Cloudflare dashboard for review. The service remains available at no extra cost across all plans, with unified settings for managing alert recipients. Cloudflare plans to expand Certificate Transparency Monitoring to Cloudflare Notifications, allowing teams to route alerts to additional destinations such as webhooks or PagerDuty.

Original source → Deals on Clipraptor.com →