#workers.dev spam
8 messages · Page 1 of 1 (latest)
Disabling is the best way.
It is because bots scrape the certification issue list so they see the ones issued to your dev domain
Ok, thanks. That was my guess. I could not see the FQDN in the TLS certificate. But maybe I looked in the wrong place.
The TLS certificate does not contain the FQDN. So somebody thought about this but then something happend.
what are you talking about? There's a unique wildcard cert for every worker, here's a few examples: https://crt.sh/?q=tylerobrien.workers.dev
Free CT Log Certificate Search Tool from Sectigo (formerly Comodo CA)
Yes, that is my conclusion too. So, the FQDN is not in the public certificate. But then there is an ordering process... Maybe the theory is a wild goosechase but somehow bots are finding the FQDN for my workers.