Skip to content

Ward opens soon: join the waitlist and we'll email you the day we open.

What Ward checks

Area: Website and certificates

Certificate issuance

Certificate authorities that issued certificates for your domain in the last 90 days (public certificate logs), and whether they match the ones your CAA record allows or the ones you have always used.

What it can report

Open each one to see what it means and how to fix it.

Certificate issued outside your CAA

What it means

example.com has a CAA record that lists which authorities (companies that issue HTTPS padlock certificates) may issue certificates for it. a certificate authority isn't on that list, yet it issued one recently. Authorities are required to respect the list.

What could happen

A certificate you didn't ask for can be used to impersonate your website or listen in on its traffic. It could also mean someone briefly changed your CAA record to get it, or that a record was tightened after the certificate was issued. It needs checking soon, even if the explanation turns out to be harmless.

How an attacker would use it

Someone who got into your DNS for a moment edits the list so a certificate can be issued for your domain, then puts it back. With that certificate, they publish a copy of your website that shows the padlock, and your customers see nothing wrong when they enter their details.

How to fix it

  1. Ask your web provider and your team whether anyone requested a certificate from a certificate authority.The technical details show when it was issued and for which names.
  2. If someone did, add that authority to your CAA record so it's allowed from now on.
  3. If nobody recognizes it, contact a certificate authority and ask it to revoke the certificate.Authorities have a page for reporting wrongly issued certificates.
  4. Review who can edit your DNS and your hosting, and change those passwords. Turn on two-step verification.
  5. Look at your DNS provider's change history, if it has one, for edits to the CAA record you don't recognize.

How to check it's fixed

Ward reviews the latest certificates against your CAA record again. Mark the finding as “Pending verification” and Ward will check it again. DNS changes can take a few hours to spread, so if it still shows up, try again later.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Certificate from a new authority

What it means

A recent HTTPS certificate for example.com was issued by a certificate authority, an authority that had never issued yours before. Your domain doesn't have a CAA record limiting who can do it. This is a guide, not a confirmed problem.

What could happen

Most often it is harmless: your hosting or CDN provider changed authorities. But it's also what happens when someone obtains a certificate improperly to impersonate you, so it's worth a quick check. Severity is medium because we can't tell which case it is.

How an attacker would use it

Someone who has taken over your DNS or hosting for a moment asks an authority for a certificate for your main website. Nothing limits which authority may issue it, so it is granted. They use it on a copy of your site that shows the padlock, and your customers can't tell it from the real one.

How to fix it

  1. Ask your web provider whether they requested the certificate from a certificate authority.Hosting platforms and CDNs sometimes switch authorities without announcing it.
  2. If they did, you can leave it. Consider adding a CAA record so only the authorities you use can issue certificates.
  3. If nobody recognizes it, treat it as an incident: ask the authority to revoke it and review who has access to your DNS and hosting.
  4. Add a CAA record with the authority you really use, so no other can issue certificates for your domain.Check with your hosting provider first that you list every authority it uses.

How to check it's fixed

Ward reviews the latest certificates again. Mark the finding as “Pending verification” and Ward will check it again. DNS changes can take a few hours to spread, so if it still shows up, try again later.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.