Good Roots Work

Certificate Transparency monitoring

Know when certificate issuance is abnormal — not just when it happens

Good Roots Work monitors Certificate Transparency logs for your domains, compares issuance against CAA policy and history, and alerts your team only when something looks wrong. Operated by Cavalry Scout Pty Ltd.

Domain Analysis

Enter your apex domain for a free sneak peek — request the complete report by email.

Valid card required — Community plan is $0

Add domains to watch

Register the domains and name patterns you care about. We ingest Certificate Transparency logs continuously.

Apply issuance policy

We evaluate each certificate against public CAA (when present), your private policy, and historical issuance patterns.

Alert on anomalies only

Expected renewals stay quiet. Unexpected CAs, new name sets, or policy violations trigger notifications and integrations.

Anomaly-only alerting

We surface unexpected certificate issuance — not every routine renewal — so your team stays focused on real risk.

Public and private CAA policy

Use DNS CAA where available, and define private issuance policy per tenant when you need stricter control than public DNS allows.

Issuance history

Track whether a certificate or name set was seen before, whether the issuing CA changed, and whether issuance follows an expected cadence.

Built on Certificate Transparency

Monitoring is powered by CT log ingestion (via our ctlogdaemon pipeline) and analysis — not periodic certificate store scraping alone.

ThePublic CAA Policy tooltool is available for everyone. Need enterprise features?Talk to sales.