Certificate Transparency monitoring
Good Roots Work monitors Certificate Transparency logs for your domains, compares issuance against CAA policy and history, and alerts your team only when something looks wrong. Operated by Cavalry Scout Pty Ltd.
Enter your apex domain for a free sneak peek — request the complete report by email.
Enter your email to unlock the full detailed report on this page and receive a copy by email. We use your address only to deliver the report and occasional product updates you can opt out of.
Want continuous monitoring?Start free
Valid card required — Community plan is $0
Register the domains and name patterns you care about. We ingest Certificate Transparency logs continuously.
We evaluate each certificate against public CAA (when present), your private policy, and historical issuance patterns.
Expected renewals stay quiet. Unexpected CAs, new name sets, or policy violations trigger notifications and integrations.
We surface unexpected certificate issuance — not every routine renewal — so your team stays focused on real risk.
Use DNS CAA where available, and define private issuance policy per tenant when you need stricter control than public DNS allows.
Track whether a certificate or name set was seen before, whether the issuing CA changed, and whether issuance follows an expected cadence.
Monitoring is powered by CT log ingestion (via our ctlogdaemon pipeline) and analysis — not periodic certificate store scraping alone.
ThePublic CAA Policy tooltool is available for everyone. Need enterprise features?Talk to sales.