Cloudflare Certificate Transparency Monitoring is now generally available. It watches public certificate records for a Cloudflare zone and alerts you when a certificate appears that Cloudflare did not issue through its automated systems. Cloudflare now filters its own managed issuances before sending these alerts, which makes the remaining notices more useful for a real review.
This is a calm, defensive checklist for website owners, agencies, and hosting teams. An alert is an investigation signal, not proof that a site has been compromised. Give it a clear owner, compare it with your approved certificate records, and use the normal change and incident process before making any service change.
Decide who owns the alerts
Start with the production domains that matter most: customer sites, online stores, client portals, and administration services. For each zone, record the person responsible for Cloudflare, the person responsible for certificates, and an escalation contact who can confirm an approved change.
- Keep a simple certificate inventory with the domain, responsible team, approved certificate provider, renewal owner, and next review date.
- Use a shared alert mailbox or a documented support queue that is reviewed during normal business coverage.
- Make sure an agency or former contractor is not the only person who can explain a certificate-related change.
- Keep this monitoring work separate from unrelated cache, crawler, or application changes.
Enable Certificate Transparency Monitoring
- Sign in to the Cloudflare dashboard and select the correct zone.
- Open SSL/TLS, then Edge Certificates, then Certificate Transparency Monitoring.
- Turn on monitoring and confirm the alert recipients shown for the zone.
- Record the enablement date and owner in the site’s operations notes.
Cloudflare says the feature is available on every plan at no extra cost. Teams already using it do not need to migrate; Cloudflare’s new filtering is already enabled for them. The current delivery method is email, so an address that nobody reads defeats the point of an otherwise useful control.
Handle an unexpected certificate alert
When a notice arrives, first compare it with your inventory and recent approved changes. A certificate that was expected for a new provider, a planned migration, or a documented service can be recorded and closed through the normal change process.
When nobody recognizes the certificate, assign the review to the Cloudflare and certificate owners immediately. Confirm the domain covered by the alert, check recent approved work, and review the registrar, DNS, certificate-provider, and account-access records that your team normally maintains. Preserve the alert and the review decision in the incident record.
Do not turn off TLS, remove DNS records, or revoke a certificate from a single alert alone. First establish what was issued, whether it was approved, and which owner is responsible. If the event cannot be explained promptly, follow the organisation’s security escalation path and involve the appropriate domain, identity, and hosting contacts.
Keep WordPress and hosting operations organized
Certificate monitoring complements ordinary website maintenance; it does not replace it. For a WordPress site behind Cloudflare, keep delivery and cache work documented with the Cloudflare CDN for WordPress guide. When a site needs a planned certificate installation, use the WordPress SSL certificate installation guide and update the certificate inventory when the work is complete.
More practical recovery, maintenance, and troubleshooting guides are collected in the Fix I.T. Phill WordPress Support hub. Cloudflare crawler policy is a different operational decision; keep it in the separate Cloudflare crawler controls checklist rather than changing it while responding to a certificate notice.
Verify the setup without causing a service interruption
- Confirm the correct Cloudflare zone has monitoring enabled.
- Confirm the alert recipient and the escalation owner can both be reached.
- Check that your certificate inventory identifies the normal issuer and renewal path for important domains.
- Schedule a short recurring review of open certificate notices and ownership changes.
There is no need to force a certificate event just to test the feature. A documented dashboard check, working alert ownership, and a current inventory provide a safer operational baseline.
Cloudflare Certificate Transparency Monitoring FAQ
Do existing users need to change anything?
No. Cloudflare says that existing users do not need to take action because filtering for Cloudflare-managed issuances is already enabled.
Does an alert prove my website was hacked?
No. It means an external certificate appeared in a public certificate record and needs to be compared with your approved work. Treat it as an alert worth investigating, then document the outcome.
Does this replace certificate renewal management?
No. Keep normal certificate ownership, renewal, access review, and website verification processes. Monitoring helps you notice a certificate that does not match those records.
Where is the official Cloudflare announcement?
See Cloudflare’s Certificate Transparency Monitoring general-availability announcement for the current feature behavior, plan availability, and dashboard location.
