The monitor can reveal an unexpected certificate for a domain, but it does not prevent issuance or revoke certificates.
On August 13, Cloudflare moved Certificate Transparency Monitoring from public beta to general availability. The service is included with every plan and had already been enabled for more than 650,000 customer domains.
The monitor scans public Certificate Transparency logs and sends an email when it finds a new certificate for a domain. The message includes the affected hostname, certificate details, and a link to the Cloudflare dashboard.
The GA version filters certificates issued by Cloudflare itself, reducing noise from routine issuance and renewals. Certificates issued elsewhere, including unexpected ones, continue to trigger alerts.
CT monitoring does not prevent a certificate authority from issuing a certificate and cannot revoke one. A suspicious alert should be checked against the hostname and issuer before the certificate authority is contacted. Email is the current notification channel; webhooks and PagerDuty integration remain future plans.