RoastMyOpsec

Safety

Expect-CT vs Certificate Transparency for Public TLS

September 6, 2023

Expect-CT vs Certificate Transparency is a leftover header versus a living ecosystem. Expect-CT told browsers to require CT evidence and optionally report failures. Chrome dropped enforcement; MDN marks the header obsolete. Shipping Expect-CT today is cargo-cult OPSEC. Certificate Transparency logs still record publicly trusted certificates. Operators should monitor new issuance for their names (CA mail, crt.sh-style search, or a vendor) and keep CAA tight. RoastMyOpsec's TLS check is HTTPS plus trust-store acceptance at scan time. It does not send Expect-CT, does not query CT logs, and does not watch expiry for you — see certificate expiry vs HSTS.

The practical difference

Expect-CT was a browser policy header. CT is a set of append-only logs CAs submit to. You can have CT without Expect-CT — that is the current world. You cannot resurrect Expect-CT into a useful control.

A surprise certificate in a log is an inventory event. It may be a CDN, a forgotten load balancer, or something you should revoke. CAA limits who should issue; CT helps you notice who did.

How to choose what to operate

Delete Expect-CT from the CDN template. Turn on issuance alerts at your CA or a CT monitor. Keep CAA current. Automate renewal. Do not add Expect-CT to a header checklist in 2026.

ControlStatusJobTakeaway
Expect-CT headerObsoleteNone in modern browsersRemove it
CT logsCurrent for public CAsPublic record of issuanceMonitor names you own
CAACurrentWho may issueSee CAA vs registrar lock
HSTS + live certCurrentThis visit's transportSee expiry vs HSTS

What the roast can see

TLS scheme and trust at scan time. Presence of Expect-CT is not a score bonus. Absence of CT monitoring is outside the HTTP response.

Common mistakes

The first mistake is a 2018 header pack that still requires Expect-CT.

The second mistake is ignoring a CT alert because 'we use Let's Encrypt.'

The third mistake is Expect-CT report-uri to an unattended inbox.

Free audit the URL you own

RoastMyOpsec is a defensive public-surface roast: headers, cookies, sensitive paths, and more — no exploit payloads. Start with the free audit, then open the vault if the blurred findings look expensive.

Free audit now

FAQ

Should I enable Expect-CT?
No. The header is obsolete. Monitor Certificate Transparency and CAA instead.
Does RoastMyOpsec check CT logs?
No. The TLS check is HTTPS and trust-store acceptance. Watch issuance in your CA or a CT monitor.
Is a CT-logged cert a vulnerability?
Logging is normal for public CAs. A cert you did not request is the finding — inventory and revoke if needed.

Sources

Related guides