Reviewed September 2026

SSLMate Cert Spotter review: a security tool that happens to watch expiry

Every other tool on this list asks when your certificate expires. Cert Spotter asks a different question entirely: has anyone issued a certificate for your domain that you did not authorise? It watches the public Certificate Transparency logs continuously, and it will tell you about a certificate you never ordered — which is either a misconfiguration or somebody preparing to impersonate you.

From $5 a month · No check quotas · Set up in under a minute

Is SSLMate Cert Spotter worth it?

If unauthorised issuance is a risk you are actually managing, yes, and there is very little competition at this level. It is the reference implementation for Certificate Transparency monitoring and the open-source CLI means you can run the core of it yourself. But understand what you are buying: this is a security product. At $15 a month for 20 endpoints and $100 for 150, it is expensive next to expiry monitors, because expiry is not what it is for.

4.5/ 5
Best in class at a job most tools do not attempt Our assessment, written by the team behind a competing product — read it as an informed opinion, not a neutral audit. Every factual claim is checked against SSLMate Cert Spotter's own public pricing and documentation at the time of writing.
Overview

What SSLMate Cert Spotter is

Certificate Transparency is a public, append-only record of certificates as they are issued. Every publicly trusted certificate for your domain lands in it, whether or not you were the one who asked for it.

Cert Spotter watches those logs continuously and alerts you when a certificate appears for a domain you own. If you did not order it, that is worth investigating immediately — it can mean a shadow IT deployment, a misconfigured CA integration, or an attacker who has obtained a valid certificate for your domain.

It does certificate health checks and expiry alongside, so it is not purely a security feed. But expiry is the secondary function here, and pricing it against ordinary expiry monitors misreads the product.

Capabilities

What Cert Spotter does well

Continuous visibility into every certificate issued for your domains.

Continuous CT log monitoring

Alerts on certificates issued for your domains, authorised or not. This is the core function and almost nothing else in the monitoring category attempts it.

An open-source CLI

The certspotter tool is published on GitHub, so the core monitoring can be self-hosted. Unusual transparency for a commercial product.

Health checks at increasing frequency

Hourly on Hobbyist, every 15 minutes on Startup, every 5 minutes on Business.

Webhook and SIEM integration

Alerts can be routed into security tooling rather than only into somebody's inbox, which is where issuance alerts belong.

DNS and registrar integrations

From the Startup tier, so the endpoint list can be built from what you actually own rather than maintained by hand.

Alert routing by type

Different alert types can go to different teams, so security notifications and expiry reminders do not end up in the same ignored mailbox.

Cost

What SSLMate Cert Spotter costs

Four tiers by endpoint count, with a 30-day trial on all of them.

Plan Price Endpoints Notes
Hobbyist $15/mo 20 Hourly health checks, 30-day audit log
Startup $100/mo 150 15-minute checks, DNS and registrar integrations, webhooks
Business $500/mo 1,000 5-minute checks, unlimited ports and IPs, 10 monitoring locations
Enterprise Quote Custom Tailored

Monitoring vendors change plan limits and prices frequently and without announcement. Every figure here carries a "verify on their site" caveat and you should take it seriously before making a decision on cost.

The balance

Where it is strong, and where it is not

What works

  • The reference tool for Certificate Transparency monitoring, with no real equivalent at this level.
  • Detects certificates issued for your domains that you never authorised.
  • Open-source CLI available on GitHub for self-hosting the core function.
  • Webhook and SIEM routing, with alerts separable by type and team.
  • Health check frequency scales meaningfully with the tier.

What to watch out for

  • Expensive if you only want expiry alerts, which are available free elsewhere.
  • The jump from $15 to $100 a month between tiers is steep for a growing estate.
  • No uptime monitoring, page monitoring or status pages.
  • Aimed at security teams, and the framing assumes that context.
  • No permanent free tier, only a 30-day trial.
Fit

Who SSLMate Cert Spotter is for

Choose it if

  • Security teams treating unauthorised issuance as a real threat.
  • Organisations with a large domain portfolio and several teams able to request certificates.
  • Anyone needing certificate alerts routed into a SIEM rather than an inbox.
  • Teams who want the option of self-hosting the monitoring core.

Look elsewhere if

  • Anyone whose actual question is when a certificate expires.
  • Small sites, where $15 a month for 20 endpoints is poor value against free alternatives.
  • Teams wanting uptime and certificates from one tool.
  • Estates between 20 and 150 endpoints, who pay the $100 tier for headroom they do not use.
Disclosure

Where MonitoringDaddy fits

These are different products and we want to be clear about it. We have no Certificate Transparency monitoring at all. If somebody obtains a certificate for your domain tomorrow, Cert Spotter will tell you and we will not — there is no configuration of our product that changes that. For unauthorised issuance, they are the tool and we are not in the conversation.

What we cover is the operational side: the certificate at your endpoint, whether it is close to expiry, whether it has already expired, and whether the check itself has stopped working — alongside uptime, domain expiry, page changes and heartbeats, from $5 a month.

The honest split: these are complementary rather than competing. A security team with a real issuance risk should use Cert Spotter for that and does not need us to duplicate it. A small team asking whether the site is up and the certificate is current is buying a different product, and $15 a month for 20 endpoints of CT monitoring is not the answer to that question.

See it

What an alert actually looks like

Every recorded change is compared word by word and kept with a before-and-after image. This is the real output, shown with worked example data.

competitor.com/pricing Watching: Pricing table
Pro plan — $49 per month
+ Pro plan — $39 per month
+ Save 20% with annual billing

Price fell from $49 to $39, and an annual discount was added.

2 words added · 1 removed · 4.1% of the watched region

retailer.com/product/… Watching: Availability
Out of stock
+ In stock — ships tomorrow
+ Add to basket

The item is available again and the basket button returned.

6 words added · 3 removed · 12.5% of the watched region

supplier.com/subprocessors Watching: Subprocessor list
~ Data is processed in the EUthe EU and the United States
+ Added: Northwind Analytics Inc. (United States)

A new subprocessor was added in another jurisdiction.

9 words added · 2 removed · 1.8% of the watched region

Worked example — not live data. Start monitoring free
Alerts

Where we can reach you

The free plan sends to one email address. Every paid plan adds the chat and webhook channels below, with 2 to 10 destinations depending on the plan. However many alerts you receive, the price does not change — nothing here is metered or charged per alert.

Email Before and after images inline
Browser push On a phone or desktop lock screen
RSS feed Every recorded change, as a feed
SlackPaid Through an incoming webhook
Microsoft TeamsPaid Through an incoming webhook
DiscordPaid Through an incoming webhook
TelegramPaid Straight to a chat or channel
FlockPaid Through an incoming webhook
WebhooksPaid Post to anything you run yourself

There are no voice calls and no SMS. If a phone call at 3am is a hard requirement, say so before you subscribe — we would rather tell you now than refund you later.

FAQ

SSLMate Cert Spotter review: your questions answered

What is Certificate Transparency?

A set of public, append-only logs recording certificates as certificate authorities issue them. Every publicly trusted certificate for your domain appears in them, which makes it possible to detect certificates issued without your knowledge.

What does Cert Spotter cost?

Hobbyist is $15 a month for 20 endpoints, Startup $100 for 150, Business $500 for 1,000, and Enterprise is quoted. All tiers include a 30-day trial. Verify current pricing on their site.

Is there a free version?

Not as a hosted plan, but the certspotter CLI is open source on GitHub and can be self-hosted. That covers the core CT monitoring without a subscription, at the cost of running it yourself.

Why would someone issue a certificate for my domain?

Innocently, through a team deploying something without telling anyone, or a cloud service provisioning one automatically. Maliciously, as preparation for impersonating your site. Both are worth knowing about, and only CT monitoring surfaces either.

Does Cert Spotter monitor uptime?

No. It does certificate health checks and CT monitoring. Whether your site is actually responding is a different question and a different tool.

Is it overkill for a small website?

Usually, yes. If you control all certificate issuance yourself and the estate is small, the risk it addresses is low and free expiry monitoring will serve you better.

How does it compare with Red Sift Certificates Lite?

Red Sift Lite is free and covers 250 certificates for expiry. Cert Spotter is paid and covers issuance detection, which Red Sift reserves for its enterprise product. Different jobs at very different prices.

How does it compare with MonitoringDaddy?

We do not do Certificate Transparency monitoring at all, so for unauthorised issuance there is no comparison to make. We cover certificate expiry, expired certificates, failed checks, uptime, domains and page changes from $5 a month.

Keep reading

Related reading

Last updated August 2026 · Written by Amit Gupta, founder of MonitoringDaddy

AG
Written by

Amit Gupta

Amit Gupta is the founder of MonitoringDaddy , a website and infrastructure monitoring platform built by TotosLocal One Private Limited. He writes about uptime, change detection, SSL and domain monitoring, and helps teams keep their websites fast, secure and online.

We watch the certificate on your server, not the transparency logs.

Cert Spotter is the tool for unauthorised issuance. For expiry, uptime, domains and page changes, start at $5 a month.