A Signed Certificate Timestamp (SCT) is a log’s signed promise that it will add a submitted TLS certificate or precertificate to its public, append-only Certificate Transparency (CT) log within the log’s Maximum Merge Delay. CT makes publicly trusted certificate issuance observable so browsers, domain owners and monitors can audit it. An SCT is not proof that the entry has already been included, that anyone has checked it, or that a misissued certificate will be revoked.
This guide explains the mechanism, current browser-policy distinctions, what website operators normally need to configure, and how to look for certificates issued for a domain.
What is a Signed Certificate Timestamp?
An SCT is a cryptographically signed statement returned by a CT log after it accepts a certificate or precertificate submission. It records the log identity, a timestamp and a signature over the certificate data. The signature commits the log to adding that accepted entry to its append-only log within the log’s declared Maximum Merge Delay (MMD).
The commitment is important but limited. An SCT is not an inclusion proof and does not by itself show that the certificate is already present in the log’s Merkle tree. Auditors later use signed tree heads, inclusion proofs and consistency checks to verify that the log kept its promise and did not present conflicting histories.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
What an SCT does not guarantee
- It does not prevent a certificate authority (CA) from issuing a wrong certificate.
- It does not prove that a monitor has noticed the issuance.
- It does not automatically revoke a certificate or shut down an attacker’s access.
- It does not make names in a certificate secret; publicly trusted certificates and their covered names are intended to be observable.
How does Certificate Transparency work?
CT is public auditing infrastructure for publicly trusted TLS server certificates. The basic flow has four independent roles:
- Certificate authority: submits a certificate or precertificate to one or more logs.
- Log operator: validates the submission, returns an SCT, and later publishes the entry in an append-only Merkle-tree log.
- Monitor: watches log entries and log behavior, looking for certificates that cover particular domains or signs of log misbehavior.
- Client: a browser or platform checks the SCTs presented with a certificate against its own policy and trusted-log information.
Merkle trees let an auditor verify both inclusion of a particular certificate and consistency between successive log views. A log that issues an SCT but fails to publish the promised entry, or presents incompatible tree histories, can therefore be detected. CT increases visibility; it is not a replacement for CA controls, domain security or incident response.
Certificate, precertificate and SCT
The submitted object may be a final certificate or a precertificate used during issuance. The SCT binds the log’s commitment to the submitted certificate data. The certificate itself remains the CA’s signed authorization for a TLS identity; the SCT is evidence of a log commitment around that authorization. Keeping those objects conceptually separate avoids treating CT as another certificate authority.
RFC 9162, RFC 6962 and today’s deployed policies
RFC 9162, published in December 2021, describes Certificate Transparency version 2.0 and obsoletes RFC 6962. RFC 9162 is published as Experimental rather than Internet Standards Track. That protocol revision does not mean every browser, platform or log immediately uses identical requirements.
Browser and platform policies can continue to reference RFC 6962 behavior and specific approved-log programs. For an operational decision, use the policy belonging to the client you must support and check its current log list; do not infer a universal rule from the RFC version number alone.
Apple’s policy
Apple’s published Certificate Transparency policy evaluates SCT count, log approval status, delivery, certificate lifetime and log-operator diversity. For relevant publicly trusted TLS certificates, Apple requires at least two SCTs from logs that were approved in the applicable time frame, with at least one SCT from an RFC 6962-compliant log. Its lifetime table treats the validity interval inclusively and defines a day as 86,400 seconds.
| Certificate validity category in Apple’s policy | Distinct-log requirement | Qualification |
|---|---|---|
| 180 days or less | Two SCTs from distinct logs | Subject to Apple’s approval and presentation conditions |
| 181 to 398 days | Three SCTs from distinct logs | Limits apply to how many SCTs from one log operator count |
These are Apple’s requirements for the certificates covered by its policy, not a rule that every TLS client follows.
Chrome’s policy
Chrome evaluates SCT number and source together with the state of the issuing logs. Its log states include Pending, Qualified, Usable, ReadOnly, Retired and Rejected. Whether a certificate satisfies CT depends on the relevant log state and timing, so consult Chrome’s maintained CT policy and log list when diagnosing a live deployment.
Do I have to configure CT on my website?
Usually, no separate site configuration is required. A publicly trusted CA normally obtains SCTs during issuance, and a cloud TLS terminator may handle their presentation. Chrome recommends certificate-embedded SCTs. If your browser reports that a certificate is missing required CT information, contact the CA’s support or sales team and ask it to diagnose the certificate and SCT delivery.
When operator action is still necessary
- Confirm that your CA or TLS provider supports the browser and platform policies you must meet.
- Check a real certificate served by each production endpoint, especially after moving TLS termination or renewing a certificate.
- Decide how your organization will monitor certificates covering your domains and who responds to an alert.
- Document which names may appear publicly; CT is not a confidentiality mechanism for hostnames.
How do I check certificates issued for my domain?
A one-time search answers “what has appeared in public CT logs?” Ongoing monitoring answers “tell me when a new certificate appears.” Use both for important domains: search first to establish a baseline, then subscribe to alerts or operate a monitor that covers the names and certificate forms you care about.
Step 1: define the names to investigate
List the registrable domain, common subdomains, wildcard forms and any alternate names used by applications. Certificate Transparency records the names covered by certificates, so include names that might be issued by a CDN, cloud load balancer or separate business unit.
Step 2: perform a public CT search
Use a reputable CT search service or monitor directory to query the exact domain and review certificates and precertificates. Treat the result as an inventory, not as proof that every listed certificate is currently valid or deployed. Check the certificate’s issuer, validity interval, serial number and Subject Alternative Name list against your own records.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Step 3: verify an unfamiliar certificate
- Compare the issuer and names with your CA accounts, hosting provider and recent change tickets.
- Ask the relevant team whether the certificate was requested for a migration, test environment or delegated service.
- If nobody recognizes it, contact the issuing CA promptly and follow its suspected-misissuance process.
- Assess whether the certificate is active on an endpoint and whether replacement or revocation is required.
An SCT or CT search result alone cannot perform those response actions. The RFC explicitly warns that a signed timestamp does not ensure a monitor checked the log or that a CA will revoke a bad certificate.
Step 4: make monitoring continuous
Choose a monitor that states which domains and certificate types it covers, how quickly it alerts and where notifications go. Assign an owner, an escalation path to the CA and a time-bound decision process. Cloudflare, for example, documents an opt-in Certificate Transparency Monitoring feature; other monitor directories list services, but coverage and alert behavior must be verified with each provider rather than assumed equivalent.
What CT reveals about your organization
Public logging makes certificate contents searchable. Domain names in certificates—and, in some cases, organization information—can therefore reveal hostnames you did not intend to advertise. Before requesting a publicly trusted certificate, decide whether each name is suitable for public disclosure. CT cannot keep an internal hostname confidential; use a certificate and trust design appropriate to that requirement.
Troubleshooting common CT problems
Chrome reports a CT-required or missing-SCT error
Likely cause: the certificate lacks the SCT presentation Chrome expects, or one of its SCTs comes from a log state that does not satisfy current policy.
Fix: capture the certificate served by the affected endpoint, identify the issuer and SCT source, then open a case with the CA or TLS provider. Ask it to check SCT embedding, log qualification and the certificate’s issuance time. Do not assume that installing the same certificate on another endpoint will repair a missing SCT.
Apple clients fail while other browsers work
Likely cause: Apple’s lifetime, distinct-log, operator-diversity or approval rules differ from the policy used by the other client.
Rank #4
Fix: classify the certificate under Apple’s validity bands, count SCTs from distinct logs and operators, and verify that at least one comes from an RFC 6962-compliant log as required by Apple’s policy. Have the CA reissue if the certificate does not meet the applicable conditions.
A CT search shows a certificate nobody recognizes
Likely cause: legitimate issuance by a forgotten vendor, CDN or subsidiary—or possible misissuance.
Recommended Free Tools
Fix: check the names, issuer, dates and serial number against internal records, contact the issuer, and follow your incident-response plan. Preserve the CT record and related CA correspondence. Do not wait for an SCT to disappear; public logs are designed to retain an auditable history.
A monitor did not alert
Likely cause: the monitor does not cover the exact name or certificate form, has a delivery failure, or the log entry has not yet reached its search index.
Fix: verify coverage and notification settings, run an independent CT search, and test the alert route. Keep a second contact or escalation channel for high-value domains.
A certificate appears in a retired or rejected log
Likely cause: the log’s state changed after issuance, or a client policy no longer counts that log.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesBest Value
Fix: evaluate the certificate using the client’s policy and the log state at the relevant times. Ask the CA whether a replacement certificate with SCTs from currently acceptable logs is needed.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Performance, reliability and operational cost
For most site owners, CT adds no request-time service to operate: the CA and TLS terminator handle issuance and presentation. The operational cost is monitoring and response. A useful program has a complete domain inventory, independent alert delivery, a named responder and a tested CA-escalation procedure.
Log operators, rather than ordinary website owners, carry the heavier reliability obligations: honoring MMD commitments, maintaining availability, preserving append-only behavior and providing consistency that auditors can verify. Clients may continue to recognize different log states during ecosystem transitions, which is why policy-specific checks matter.
Or skip the browser setup
If you need a visual record of a public CT results page or another web page for an incident ticket, ScreenshotNeo can capture it with one request. Its API accepts a URL and returns PNG, JPEG, WebP or PDF; the documentation is at screenshotneo.com/docs/.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Example using a public CT search URL:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://crt.sh/?q=example.com -o shot.webp
Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://crt.sh/?q=example.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://crt.sh/?q=example.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
- Cookie banners, newsletter popups and chat widgets are removed before the shot.
- Bot checks, blank pages and failed loads are never billed; response headers identify the page verdict and billing status.
- An MCP server lets Claude, Cursor and other MCP clients take screenshots with
take_screenshot, inspect pages withget_page_infoand create PDFs withcapture_pdf. - The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000 shots.
Sign up for ScreenshotNeo free to archive CT evidence without setting up a browser.
FAQ
Frequently Asked Questions
Is an SCT the same thing as a certificate?
No. A certificate is the CA-signed TLS authorization; an SCT is a CT log’s signed commitment to publish the submitted certificate or precertificate within its MMD.
Does Certificate Transparency make certificate issuance private?
No. CT deliberately makes publicly trusted certificate contents and covered names observable.
Can I revoke a certificate through a CT log?
No. Contact the issuing CA and use your incident-response process; CT provides visibility and auditability, not revocation.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallWhich CT policy should I follow?
Follow the policy of the client or platform you must support, such as Apple’s or Chrome’s, and check its current approved-log information.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

