certspotter Commands Reference

Local Certificate Transparency monitor from SSLMate. Alerts when new certificates appear for domains you watch โ€” run it as a daemon, not a cron job.

๐Ÿ“ฆ Installation

go install software.sslmate.com/src/certspotter/cmd/certspotter@latest
go install software.sslmate.com/src/certspotter/cmd/certspotter-authorize@latest

๐Ÿ‘€ Watchlist

Default path: ~/.certspotter/watchlist. Restart certspotter after edits.

# .example.com     โ†’ apex + all subdomains
# www.example.com  โ†’ exact name only
printf '%s\n' '.example.com' 'www.other.com' > ~/.certspotter/watchlist
echo '[email protected]' > ~/.certspotter/email_recipients
mkdir -p ~/.certspotter/hooks.d

๐Ÿš€ Run as a daemon

# Prefer -start_at_end to skip the historical CT backlog
certspotter -start_at_end
certspotter -start_at_end -email [email protected] -verbose
certspotter -watchlist /etc/certspotter/watchlist -state_dir /var/lib/certspotter

Use systemd with Restart=always. Do not schedule certspotter itself via cron.

โœ… Authorize known certs

certspotter-authorize /path/to/cert.pem

Marks a certificate as expected so subsequent CT sightings are quieter. Test with watch entry .test.certspotter.org.

๐Ÿ”— See Also

Docs: github.com/SSLMate/certspotter ยท Hosted: sslmate.com/certspotter