Observed arrival · 2026-08-24
Merkleye, a watchtower for certificates you did not authorize
Credibility concern recorded. The source reference remains available for verification and correction.
A self-hosted Certificate Transparency monitor that watches for unexpected certificates and lookalike domains before they become phishing infrastructure.
Field notes
The monitor processes certificates as they appear in the CT stream, comparing them with a locally configured domain hash set and retaining only matches. The page emphasizes several operational choices: issuer checks use case-insensitive substring matching, domains are normalized to punycode, and deduplication keys on the certificate’s SHA-256 DER hash. It also frames dnstwist coverage as the reason a firehose model can handle about 100,000 lookalike variants without issuing 100,000 separate API requests.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue