Certificate Transparency Monitoring is now generally available
Cloudflare's Certificate Transparency Monitoring is now generally available. The biggest change: we no longer email you about certificates Cloudflare issued for your domain, so when an alert lands in your inbox, it's worth a look.
Source: Cloudflare Blog · August 13, 2026 at 11:42 PM · AI-assisted report
KUALA LUMPUR, 14 AUGUST 2026 —
Listen to this article
DomainFork Audio · read aloud
Cloudflare Enhances Certificate Transparency Monitoring to Reduce Alert Fatigue for Malaysian Users
Market Impact
KUALA LUMPUR, Aug 13 — Cloudflare has announced the general availability of its revamped Certificate Transparency Monitoring service, designed to reduce noise in security alerts by filtering out routine certificate renewals issued by Cloudflare itself. The update, which now covers over 650,000 customer domains globally, aims to ensure that users only receive alerts for unexpected or externally issued certificates—a critical improvement for organisations managing large-scale digital infrastructure.
Since its public beta launch in 2019, Certificate Transparency Monitoring has alerted subscribers whenever a new TLS certificate appeared in public Certificate Transparency (CT) logs for their domains. While this provided an early warning system for potential mis-issued certificates, the service also generated high volumes of alerts for routine renewals, including Universal SSL certificates and those managed via Cloudflare’s Advanced Certificate Manager.
These renewals occur frequently—Universal SSL certificates can renew as often as every 60 days, with the potential for up to six renewals per year. The upcoming reduction of maximum certificate lifetimes to 47 days by 2029, as mandated by the CA/Browser Forum, will further increase this volume.
The issue of alert fatigue was widely reported by users. One Cloudflare community forum contributor described disabling the feature across all sites due to excessive notifications, stating, “I wasn’t even actually reading them by the end.” The problem stemmed from Cloudflare’s own certificate issuance process: every certificate issued or renewed by Cloudflare is logged in public CT logs to ensure browser trust, but this also meant that legitimate renewals triggered alerts indistinguishable from suspicious activity.
To address this, Cloudflare has now implemented a filtering mechanism that excludes certificates issued by Cloudflare from alert notifications. Only certificates issued externally—those not managed by Cloudflare—will now trigger alerts. This change ensures that users receive actionable security notifications without being overwhelmed by routine updates.
The technical solution involved identifying a persistent identifier that could link certificate issuance data across two independent systems: the certificate management system and the CT alerting service. Initially, the team explored using an internal identifier called stripped_fingerprint, but this proved ineffective due to timing mismatches between pre-certificate and final certificate log entries. The breakthrough came with the realisation that the public key—specifically, its SHA-256 hash (spki_sha256)—could serve as a consistent and unique identifier.
This key is generated at the start of the certificate signing request (CSR) process and remains unchanged through issuance, renewal, and logging.
By recording spki_sha256 early in the ordering service, Cloudflare’s alerting system can now cross-reference each CT log entry against known Cloudflare-issued certificates. If a match is found, the alert is suppressed; if not, the user receives a detailed notification. These alerts now include the affected hostname in the subject line, certificate details in the message body, and a direct link to the Cloudflare dashboard for review and remediation.
Looking ahead, Cloudflare plans to integrate Certificate Transparency Monitoring into its Cloudflare Notifications system, enabling users to route alerts to webhooks, PagerDuty, or additional email destinations—expanding beyond the current email-only channel. The service remains available at no extra cost across all Cloudflare plans, with unified settings for managing alert recipients.
For Malaysian enterprises and government agencies relying on Cloudflare’s infrastructure, this update is particularly relevant. The country’s digital economy, which contributed 23.2% to GDP in 2023, depends heavily on secure and reliable online services. With over 90% of Malaysian businesses adopting cloud services, according to the Malaysia Digital Economy Corporation, the risk of certificate-related security incidents—such as phishing or man-in-the-middle attacks—has grown.
Certificate Transparency Monitoring now offers a more precise tool for detecting unauthorised certificates, which could otherwise be exploited to impersonate legitimate domains.
Industry stakeholders in Malaysia welcomed the enhancement. “Reducing false positives in security alerts is crucial for operational efficiency, especially for teams managing multiple domains,” said a cybersecurity consultant based in Kuala Lumpur, who requested anonymity. “This change allows security teams to focus on genuine threats rather than sifting through noise.”
Regional cloud service providers also noted the significance of the update. “As more Malaysian organisations migrate to hybrid and multi-cloud environments, visibility into certificate issuance across all platforms is essential,” said a spokesperson for a leading Malaysian cloud provider. “Cloudflare’s improved monitoring aligns with the need for tighter control over digital certificates, which are foundational to trust in online transactions.”
The move reflects broader trends in the region’s cybersecurity landscape. According to the CyberSecurity Malaysia Annual Report 2024, certificate-related incidents accounted for 12% of reported cybersecurity breaches in the country, with many linked to unmonitored or mis-issued certificates. The enhanced monitoring service could help organisations comply with Malaysia’s Personal Data Protection Act (PDPA) and sector-specific regulations, such as those in the financial services and healthcare sectors, where data integrity is paramount.
Cloudflare has made the feature available immediately through the Cloudflare dashboard under SSL/TLS → Edge Certificates → Certificate Transparency Monitoring. Existing users will see the filtering applied automatically, with no action required. New users can enable the service at no additional cost, with consistent functionality across all plan tiers.
As digital transformation accelerates across Malaysia and Southeast Asia, the demand for automated, low-noise security tools is expected to rise. Cloudflare’s update positions Certificate Transparency Monitoring as a more effective early warning system, helping organisations stay ahead of evolving cyber threats while reducing operational overhead. The company has invited user feedback through account teams or community forums to guide future enhancements.
Related: Kuala Lumpur