ArgusLeaf

Certificate Transparency

What is Certificate Transparency, and why does every HTTPS certificate become public?

Certificate Transparency (CT) is a public logging system standardised in RFC 6962 and now required by all major browser vendors. Every certificate authority that wants browsers to trust its certificates must submit every certificate it issues to at least two public CT logs. The logs are append-only and globally readable.

The practical effect: within minutes of a domain receiving an HTTPS certificate — whether for a legitimate business, a parked domain, or a phishing site — a record appears in the public log. ArgusLeaf reads those records in near real-time. This is why phishing infrastructure is now detectable before a campaign is even active.

See how we read these logs →

Does ArgusLeaf see my private or internal servers?

No. We read CT logs only. A server with an internal, self-signed, or privately issued certificate will not appear in any public CT log and will never be visible to us. The same applies to servers using IP addresses directly, or domains that have never received a publicly trusted certificate.

Do all phishing sites use HTTPS? Will ArgusLeaf miss HTTP-only ones?

Modern browsers label HTTP sites as "Not Secure," so most phishing campaigns now use HTTPS to appear credible — and therefore appear in CT logs. Purely HTTP-only phishing is increasingly rare for campaigns targeting consumer brands, though it does still occur.

ArgusLeaf is a CT-log monitoring system, not a general-purpose phishing scanner. We will not detect phishing domains that never acquire a public certificate. We're transparent about this limitation: see Scope on the Methodology page.

Detection and scoring

What counts as a "suspicious domain"?

A domain that scores 50 or above on our similarity model after being compared against your watch-list terms. The model applies edit distance, homoglyph skeleton matching, combosquat detection, keyword signals, TLD risk, and structural signals.

A match means the domain looks statistically similar to your brand. It does not mean it is a phishing site, or that the owner has any harmful intent. Full methodology →

What are the score tiers and what do they mean?

Scores run from 0 to 100:

≥ 80 — Immediate email. A strong similarity match. We send an alert email within minutes of the certificate appearing in the log.

50–79 — Daily digest. A plausible match. Batched and delivered once per day so you can review a set at a time.

40–49 — Internal log only. A weak signal. We store it for our own analysis but don't deliver it to you.

< 40 — Discarded. Statistical noise; not stored.

Thresholds are adjustable per organisation — high-risk sectors may lower the immediate threshold.

Why did I get an alert for a domain that is obviously ours?

This is a false positive caused by your own domain matching your own brand terms. The fix is to add your domains and subdomains to your suppress-list. Suppression rules are applied before scoring, so the domain is discarded immediately and won't reappear.

Email [email protected] with your suppress-list additions and we'll apply them to your account.

False positives

How many false positives should I expect?

It depends on how common your brand terms are. A one-word brand term like "bank" will generate more noise than a distinctive coined word. For most organisations with mid-specificity brand terms, expect a handful of false positives per week in the daily digest, with the immediate-email tier staying quiet.

Our enrichment pass (HTTP + DNS) filters out non-resolving and parked domains before delivery, which substantially reduces digest noise. We're transparent that some false positives will always reach you — the alternative, raising thresholds, would also raise false negatives.

What do I do about a recurring false-positive pattern?

Email us the pattern and we'll add a suppression rule to your account. Suppression can match on exact domain, registrable domain, or substring. If the same pattern is hitting many of our tenants, we may add it to a shared allowlist.

Does a match mean the domain is phishing?

No. We report suspicion, not guilt. An alert means a domain looks statistically similar to your watch-list — nothing more. Many matches are legitimate: a competitor including your brand name in a subdomain keyword, a security researcher's test environment, a domain parked years before your brand existed.

Every alert email includes this disclaimer. Do not initiate legal action against a domain owner based solely on an ArgusLeaf alert without independent investigation.

Email and unsubscribe

How often will I receive alert emails?

At most twice per day: once for any immediate alerts (score ≥ 80), and once for the daily digest (scores 50–79). On quiet days — no matches above threshold — you receive nothing. We don't send placeholder or "no threats today" emails.

How do I unsubscribe from alert emails?

Every alert email contains a one-click unsubscribe link in its footer. Clicking it stops alert delivery immediately. Your monitoring account stays open — you can reactivate alerts by emailing us.

To close your account entirely (delete watch-list, contact data, and alert history), email [email protected] with "account closure" in the subject. See Terms §6–§7 for retention and cancellation details.

Does unsubscribing delete my account?

No. Unsubscribing stops email delivery but leaves your monitoring account open. Your watch-list continues to run; we store matches internally. To close the account and delete your data, follow the account closure process in Terms §7.

Beta limitations

How many organisations can join, and is it really free?

The first 50 organisations are monitored at no charge for the duration of the beta period. We'll give active users at least 30 days' notice before introducing any paid tier. There is no upsell, no trial expiry countdown, and no credit-card requirement to apply.

Apply for early access →

Is there an uptime or detection SLA?

No. ArgusLeaf is in public beta with no uptime, latency, or detection-completeness service level agreement. Performance targets quoted on this site (such as "< 5 min P95 alert latency") are design goals, not contractual commitments. Detection gaps and outages are expected.

See Terms §2 for the full beta disclaimer.

How do I report a bug or wrong alert?

Email [email protected] with the domain name, the score, and why you think it's wrong. Bug reports about scanner behaviour (unexpected HTTP requests to your servers) go to [email protected].

We read every message. During beta, feedback directly shapes what we build next.