Checks

Certificate Transparency lists extra names

Public Certificate Transparency logs contain names related to this host that are not on the current certificate.

Why it matters

Those names were certified at some point. They can be old hosts, forgotten subdomains, or names you did not mean to publish.

What to do

Review the names. Remove DNS for ones you no longer operate, and make sure you expect every name a CA has logged.

Reference

Public CT logs reveal certificates issued for the domain, including leftover names.

Certificate Transparency