Certificate Transparency for brand monitoring
One of the most useful early-warning signals in brand protection is hiding in plain sight, in a public log that anyone can read. It is called Certificate Transparency, and it can tell you a phishing clone of your brand is being set up — often before the page is even live. Here is how to use it.
What Certificate Transparency is
Certificate Transparency (CT) is an open framework that logs every TLS/SSL certificate a certificate authority issues. The logs are public, append-only and monitorable by anyone. CT was created to catch mis-issued or fraudulent certificates — a security check on the authorities themselves. But it has a powerful side effect for brand protection: it makes certificate issuance visible.
Why that matters for phishing
Modern phishing pages almost always use HTTPS. Attackers want the padlock in the address bar, because its absence is a warning even casual users notice. To get that padlock, the lookalike domain needs a TLS certificate — and getting one puts a public, timestamped record into the CT logs.
That certificate is often issued in the final setup step, shortly before the phishing page goes live. Watching CT logs can therefore surface a clone at the moment it prepares to launch — not days after it starts stealing credentials.
What to watch for
Monitoring CT for brand protection means scanning the stream of newly logged certificates for domains that resemble yours:
- Edit-distance matches — names one or two characters off from your domain.
- Combosquatting — your brand plus phishing keywords like
login,secure,verify,support. - Homoglyph variants — look-alike-character swaps that spell your brand to the eye.
- Suspicious subdomains — your brand buried in a subdomain of an unrelated certificate.
From a CT hit to a takedown
A CT match is a trigger, not a conclusion. The workflow after a hit:
- Investigate the domain — is it dormant, or already serving content?
- Crawl it as a bot and a real phone to defeat any cloaking and see the real page.
- Confirm impersonation and capture evidence if it is a clone.
- File the takedown — and if it is still dormant, keep watching so you are ready the instant it activates.
Phish Plug watches Certificate Transparency logs and new-registration feeds for lookalikes of your brand, then crawls each hit from dual profiles to prove any cloaking and build the case — turning CT from a raw signal into a finished takedown.
The takeaway
Certificate Transparency turns a step every phishing site has to take — getting a certificate for its padlock — into an early-warning signal you can monitor for free. On its own it just flags lookalikes; paired with dual-profile crawling and takedowns, it lets you catch clones at setup time, before they ever reach your customers.
Keep reading
Related articles
Phishing-as-a-Service (PhaaS), explained
Phishing is now a subscription product: kits, cloaking and hosting sold ready-made. What PhaaS is, why it scales attacks, and what actually stops it.
Read article Threats · 7 minSmishing: how SMS phishing works and how to fight it
Phishing by text message bets on urgency and small screens. How smishing lures work, why links are so dangerous on mobile, and how to shut down the pages behind them.
Read article Threats · 7 minVishing: voice phishing and callback scams explained
Phone-based phishing uses a human voice to bypass caution. How vishing and callback scams work, the role of spoofed numbers, and where brand protection fits in.
Read articleProtect your brand across every channel
Run a free clone check and see detection, cloaking forensics and evidence in one pass.