Should I revoke these certs?

I have received the notification from cloudflare certificate transparency notification that they observed certificates issuance which has no relations to our domain:

Cloudflare has observed issuance of the following certificate for or one of its subdomains:

Log date: 2023-12-06 07:09:34 UTC
Issuer: CN=R3,O=Let's Encrypt,C=US
Validity: 2023-12-06 06:09:34 UTC - 2024-03-05 06:09:33 UTC
DNS Names:,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,

Can anybody help me out what is happening? These are not recognized at all by our team. Should I revoke these certs? If yes, how can I achieve this?

How exactly do you propose to revoke certificates that you do not control? Generally the only time you need to revoke a certificate is if you lost control of its private key.

I have yet to see anything positive related to certificate transparency notifications. They tend to create nothing but noise and confusion.


Why did Cloudflare notify you if there is NO relation to one of your domains? I assume your domain is at least listed too, right?

If you don't know where the (sub)domain comes from, perhaps you have a security problem with your DNS? Because resolves to, which either someone from your own company added to the DNS zone of or your DNS was hacked.


These all seem to be hosted by an Atlassian SAAS product, which is presumably allowed (and required) to issue certificates for them in order to provide its service to you. In that case they are valid and expected.


That cert looks like it was issued by a service called

Your subdomain is included in it

See the cert here

Do you know who that is? It looks like a security service for financial sites.

It is not unusual for services to group multiple names in one cert.

If they are a service you use contact them.


Another clue is in the CNAME for



