CertaDNS
Glossary

Certificates

Certificate Transparency

Public append-only logs of issued certificates, which browsers require for a certificate to be trusted. This makes issuance for any name observable — including names that look like yours.

Defined in RFC 9162.

Where this appears

The lessons that use this term, and what each is for.

Advanced Email TrustVMC, CMC, and the trademarkSay what the certificate attests, what it costs, and which authorities issue it.Domain Security FundamentalsCertificate Transparency as a detection channelRead a CT log entry and say what it does and does not tell you about a domain.Domain Security FundamentalsScoping monitoring so it produces actionDefine a monitoring scope you can actually act on, and justify what you excluded.Domain Abuse & ImpersonationThe lifecycle of a phishing domainPlace a domain on its timeline from registration to abandonment, and say what that implies for response.Domain Abuse & ImpersonationReading a log entryExtract everything a Certificate Transparency entry discloses, including names nobody published.Domain Abuse & ImpersonationThe volume problemDesign a CT query that produces findings rather than a firehose.Domain Abuse & ImpersonationThe failure mode nobody budgets forExplain why a monitoring programme that finds everything protects nothing.Brand ProtectionCertificate streamsRun a certificate feed as a live channel rather than a periodic search.Brand ProtectionSignals that are costly to changeDetect a cloned site using artefacts an attacker would have to work to remove.Brand ProtectionWhere automated detection stopsSay which clone-detection decisions a person has to make, and why.Brand ProtectionWhat to capture, and in what orderAssemble a complete evidence package for a live finding before anything changes.Brand ProtectionWhat automates wellIdentify the stages of the programme that should be fully automated.Domain Trust ArchitectureThe four surfacesPlace any control on one of four surfaces, and say which surface a given attack targets.Domain Trust ArchitectureEvidence per findingRecord each finding so somebody else can verify it without repeating your work.Domain Security PractitionerThe impersonation exposureQuantify what is being registered against the brand using only public data.Domain Security PractitionerThe CNAME from 2024Work a dangling record whose original owner and purpose are both unknown.