Every other tool on this list asks when your certificate expires. Cert Spotter asks a different question entirely: has anyone issued a certificate for your domain that you did not authorise? It watches the public Certificate Transparency logs continuously, and it will tell you about a certificate you never ordered — which is either a misconfiguration or somebody preparing to impersonate you.
From $5 a month · No check quotas · Set up in under a minute
Is SSLMate Cert Spotter worth it?
If unauthorised issuance is a risk you are actually managing, yes, and there is very little competition at this level. It is the reference implementation for Certificate Transparency monitoring and the open-source CLI means you can run the core of it yourself. But understand what you are buying: this is a security product. At $15 a month for 20 endpoints and $100 for 150, it is expensive next to expiry monitors, because expiry is not what it is for.
Certificate Transparency is a public, append-only record of certificates as they are issued. Every publicly trusted certificate for your domain lands in it, whether or not you were the one who asked for it.
Cert Spotter watches those logs continuously and alerts you when a certificate appears for a domain you own. If you did not order it, that is worth investigating immediately — it can mean a shadow IT deployment, a misconfigured CA integration, or an attacker who has obtained a valid certificate for your domain.
It does certificate health checks and expiry alongside, so it is not purely a security feed. But expiry is the secondary function here, and pricing it against ordinary expiry monitors misreads the product.
Continuous visibility into every certificate issued for your domains.
Alerts on certificates issued for your domains, authorised or not. This is the core function and almost nothing else in the monitoring category attempts it.
The certspotter tool is published on GitHub, so the core monitoring can be self-hosted. Unusual transparency for a commercial product.
Hourly on Hobbyist, every 15 minutes on Startup, every 5 minutes on Business.
Alerts can be routed into security tooling rather than only into somebody's inbox, which is where issuance alerts belong.
From the Startup tier, so the endpoint list can be built from what you actually own rather than maintained by hand.
Different alert types can go to different teams, so security notifications and expiry reminders do not end up in the same ignored mailbox.
Four tiers by endpoint count, with a 30-day trial on all of them.
| Plan | Price | Endpoints | Notes |
|---|---|---|---|
| Hobbyist | $15/mo | 20 | Hourly health checks, 30-day audit log |
| Startup | $100/mo | 150 | 15-minute checks, DNS and registrar integrations, webhooks |
| Business | $500/mo | 1,000 | 5-minute checks, unlimited ports and IPs, 10 monitoring locations |
| Enterprise | Quote | Custom | Tailored |
Monitoring vendors change plan limits and prices frequently and without announcement. Every figure here carries a "verify on their site" caveat and you should take it seriously before making a decision on cost.
These are different products and we want to be clear about it. We have no Certificate Transparency monitoring at all. If somebody obtains a certificate for your domain tomorrow, Cert Spotter will tell you and we will not — there is no configuration of our product that changes that. For unauthorised issuance, they are the tool and we are not in the conversation.
What we cover is the operational side: the certificate at your endpoint, whether it is close to expiry, whether it has already expired, and whether the check itself has stopped working — alongside uptime, domain expiry, page changes and heartbeats, from $5 a month.
The honest split: these are complementary rather than competing. A security team with a real issuance risk should use Cert Spotter for that and does not need us to duplicate it. A small team asking whether the site is up and the certificate is current is buying a different product, and $15 a month for 20 endpoints of CT monitoring is not the answer to that question.
Every recorded change is compared word by word and kept with a before-and-after image. This is the real output, shown with worked example data.
Price fell from $49 to $39, and an annual discount was added.
The item is available again and the basket button returned.
A new subprocessor was added in another jurisdiction.
The free plan sends to one email address. Every paid plan adds the chat and webhook channels below, with 2 to 10 destinations depending on the plan. However many alerts you receive, the price does not change — nothing here is metered or charged per alert.
There are no voice calls and no SMS. If a phone call at 3am is a hard requirement, say so before you subscribe — we would rather tell you now than refund you later.
A set of public, append-only logs recording certificates as certificate authorities issue them. Every publicly trusted certificate for your domain appears in them, which makes it possible to detect certificates issued without your knowledge.
Hobbyist is $15 a month for 20 endpoints, Startup $100 for 150, Business $500 for 1,000, and Enterprise is quoted. All tiers include a 30-day trial. Verify current pricing on their site.
Not as a hosted plan, but the certspotter CLI is open source on GitHub and can be self-hosted. That covers the core CT monitoring without a subscription, at the cost of running it yourself.
Innocently, through a team deploying something without telling anyone, or a cloud service provisioning one automatically. Maliciously, as preparation for impersonating your site. Both are worth knowing about, and only CT monitoring surfaces either.
No. It does certificate health checks and CT monitoring. Whether your site is actually responding is a different question and a different tool.
Usually, yes. If you control all certificate issuance yourself and the estate is small, the risk it addresses is low and free expiry monitoring will serve you better.
Red Sift Lite is free and covers 250 certificates for expiry. Cert Spotter is paid and covers issuance detection, which Red Sift reserves for its enterprise product. Different jobs at very different prices.
We do not do Certificate Transparency monitoring at all, so for unauthorised issuance there is no comparison to make. We cover certificate expiry, expired certificates, failed checks, uptime, domains and page changes from $5 a month.
Last updated August 2026 · Written by Amit Gupta, founder of MonitoringDaddy
Cert Spotter is the tool for unauthorised issuance. For expiry, uptime, domains and page changes, start at $5 a month.