certspotter Commands Reference
Local Certificate Transparency monitor from SSLMate. Alerts when new certificates appear for domains you watch โ run it as a daemon, not a cron job.
๐ฆ Installation
go install software.sslmate.com/src/certspotter/cmd/certspotter@latest
go install software.sslmate.com/src/certspotter/cmd/certspotter-authorize@latest๐ Watchlist
Default path: ~/.certspotter/watchlist. Restart certspotter after edits.
# .example.com โ apex + all subdomains
# www.example.com โ exact name only
printf '%s\n' '.example.com' 'www.other.com' > ~/.certspotter/watchlist
echo '[email protected]' > ~/.certspotter/email_recipients
mkdir -p ~/.certspotter/hooks.d๐ Run as a daemon
# Prefer -start_at_end to skip the historical CT backlog
certspotter -start_at_end
certspotter -start_at_end -email [email protected] -verbose
certspotter -watchlist /etc/certspotter/watchlist -state_dir /var/lib/certspotterUse systemd with Restart=always. Do not schedule certspotter itself via cron.
โ Authorize known certs
certspotter-authorize /path/to/cert.pemMarks a certificate as expected so subsequent CT sightings are quieter. Test with watch entry .test.certspotter.org.
๐ See Also
Docs: github.com/SSLMate/certspotter ยท Hosted: sslmate.com/certspotter