List of Best

Cloudflare Launches Free Certificate Monitoring for All Plans to Stop Alert Spam

Table of contents

Cloudflare made its Certificate Transparency Monitoring feature available to everyone on August 13, 2026. If you run a website on Cloudflare, this update helps you spot unauthorized security certificates. You will not have to deal with endless alert emails.

You can read the announcement in the Cloudflare — Certificate Transparency Monitoring is now generally available blog post.

How the noise filter works

Certificate Transparency logs record every SSL certificate issued on the web. Monitoring these public logs helps you catch rogue certificates quickly. Routine renewals can happen as often as every 60 days. That quickly fills up your inbox.

Cloudflare fixes this with a built-in filter. It stops alert emails for certificates it manages for you:
– Universal SSL
– Advanced Certificate Manager
– Total TLS
– Backup Certificates

External certificates and custom certificates uploaded by customers will still trigger alerts. To tell internal and external certificates apart, Cloudflare checks a public-key hash called spki_sha256. The platform creates this hash during the issuance flow. It then checks the hash against incoming log entries.

The vendor claims you should keep in mind

Cloudflare says the feature is active for over 650,000 customer domains across all plans. There is no extra cost. These numbers and filtering claims come directly from Cloudflare’s own announcement. Nobody outside the company has run an independent audit to check for missed certificates or false negatives. A quiet inbox is not proof that your domain is secure. Treat every unsuppressed alert as a lead to investigate, not as final proof of compromise.

What is missing and what to try next

Right now, alerts arrive only by email. Cloudflare says integrations for webhooks, PagerDuty, and its central Notifications system are planned for the future. That leaves a gap for teams that need instant escalation.

Existing users already have the filter turned on. If you are adding a new domain, you can find the switch at SSL/TLS → Edge Certificates → CT Monitoring.

You can also test the system yourself. Take a test domain with two subdomains. Issue one certificate through Cloudflare and another through an external certificate authority. Then, check your inbox. Confirm that Cloudflare silences the internal renewal while sending an alert for the external one.

← All news