I bought the domain passkey.exchange through Cloudflare on 12 April and I didn't set up ANYTHING on it. No DNS records. Nothing. I didn't touch it since
Yet. Exactly at the purchase time. 3 certificates where added to the certificate transparency log:
2 from LetsEncrypt and one from Google. How?
https://crt.sh/?q=passkey.exchange
The only explanation that i have is that Cloudflare is doing some kind of integration testing after you buy a domain from them on Google Cloud and LetsEncrypt before giving you the domain.
But that means they have some private key somewhere for 90 days. Across two different CAs..
Or I have really bad memory. Set up some Infrastructure on Google Cloud and then deprovisioned it again and removed all DNS records.
Or I was hacked.
It's really strange.
Edit: digging further it must've been Cloudflare.
The google cert has
Not Before: Apr 12 22:01:51 2024 GMT
My invoice is dated 22:49 UTC. One hour after the cert was issued?