Detection

Certificate Transparency for brand monitoring

Phish Plug ResearchAugust 12, 20268 min read

One of the most useful early-warning signals in brand protection is hiding in plain sight, in a public log that anyone can read. It is called Certificate Transparency, and it can tell you a phishing clone of your brand is being set up — often before the page is even live. Here is how to use it.

What Certificate Transparency is

Certificate Transparency (CT) is an open framework that logs every TLS/SSL certificate a certificate authority issues. The logs are public, append-only and monitorable by anyone. CT was created to catch mis-issued or fraudulent certificates — a security check on the authorities themselves. But it has a powerful side effect for brand protection: it makes certificate issuance visible.

Why that matters for phishing

Modern phishing pages almost always use HTTPS. Attackers want the padlock in the address bar, because its absence is a warning even casual users notice. To get that padlock, the lookalike domain needs a TLS certificate — and getting one puts a public, timestamped record into the CT logs.

That certificate is often issued in the final setup step, shortly before the phishing page goes live. Watching CT logs can therefore surface a clone at the moment it prepares to launch — not days after it starts stealing credentials.

What to watch for

Monitoring CT for brand protection means scanning the stream of newly logged certificates for domains that resemble yours:

  • Edit-distance matches — names one or two characters off from your domain.
  • Combosquatting — your brand plus phishing keywords like login, secure, verify, support.
  • Homoglyph variants — look-alike-character swaps that spell your brand to the eye.
  • Suspicious subdomains — your brand buried in a subdomain of an unrelated certificate.

From a CT hit to a takedown

A CT match is a trigger, not a conclusion. The workflow after a hit:

  1. Investigate the domain — is it dormant, or already serving content?
  2. Crawl it as a bot and a real phone to defeat any cloaking and see the real page.
  3. Confirm impersonation and capture evidence if it is a clone.
  4. File the takedown — and if it is still dormant, keep watching so you are ready the instant it activates.

Phish Plug watches Certificate Transparency logs and new-registration feeds for lookalikes of your brand, then crawls each hit from dual profiles to prove any cloaking and build the case — turning CT from a raw signal into a finished takedown.

The takeaway

Certificate Transparency turns a step every phishing site has to take — getting a certificate for its padlock — into an early-warning signal you can monitor for free. On its own it just flags lookalikes; paired with dual-profile crawling and takedowns, it lets you catch clones at setup time, before they ever reach your customers.

Protect your brand across every channel

Run a free clone check and see detection, cloaking forensics and evidence in one pass.