CT MONITORING

Methodology

The methodology distinguishes exact processing totals from statistically estimated distinct counts, with the scope, precision and limitations of each measure stated below.

Collection

Private collectors download and verify entries from monitored public Certificate Transparency logs. They process the whole feed but retain customer-specific certificate details only when a name matches an authorised watchlist.

Raw entries and duplication

“CT log entries today” and “this month” are exact processing counters. They reset at the start of each UTC day and calendar month. They are not unique-certificate totals: the same certificate or precertificate can be submitted to multiple logs and therefore appear more than once. The cumulative processing total remains available through the public statistics API.

Approximate distinct counts

Unique certificates, DNS names, registrable domains and pair counts use compact probabilistic sketches. With the current precision, the expected relative standard error is approximately 0.20%. Estimates may move by more or less than the true change over short intervals.

CT log coverage

The configured-log total comes from the current monitored log lists used by the collectors. A configured log is counted as healthy when its locally verified state records a successful update within the preceding two hours. The active-log figure identifies configured logs whose published issuance period includes the current time. Future and recently retired shards remain configured so continuity is preserved.

Domain interpretation

A DNS name is a certificate name such as www.example.com. A registrable domain is the effective base domain such as example.com, determined using public suffix rules. Wildcards are normalised for counting.

Updates and retention

The collectors write their current summaries locally and send only scalar totals and coverage counts to this site every 15 minutes. Public history is retained for up to three years and drives the hourly, daily, monthly and growth charts. A delayed timestamp means the latest upload has not yet arrived; it does not necessarily mean collection has stopped.