Domains
A domain is a name you have proved you control. Verifying one is what puts it into the discovery rotation. Monitor your first domain walks through adding the first; this page is about living with the list afterwards.
Operators and owners only. Viewers cannot see this screen.
Reading a row
Section titled “Reading a row”Each row carries a status and a line telling you where the domain is in its cycle.
| Status | What the row says |
|---|---|
| Pending | Verify to enable recurring discovery. Anything already scanned keeps being rescanned. |
| Active | Discovery scheduled until the first pass runs, then the time of the last one and when the next is due. |
| Inactive | Discovery paused. The domain stays in your list and nothing new is enumerated for it. |
Two counters on the right show how many certificates and endpoints NoCert holds for that domain. Both link into the matching list, filtered. A CAA chip sits beside them; select it to open the drawer described below.
While a public scan is running the page shows a banner saying so. Inventory numbers move when the results land, not while the scan is in flight.
Discovery cadence
Section titled “Discovery cadence”A verified domain is re-enumerated no more often than every 48 hours. That is a floor, not a promise: enumeration is queued, and a busy queue or a failed attempt pushes it back.
Verifying a domain puts it at the front of the queue, which is why a freshly verified domain usually produces results quickly and a domain added weeks later can take longer to show anything.
You cannot force a re-run, choose what gets enumerated, or change the cadence.
Certificate authority authorization
Section titled “Certificate authority authorization”Where a domain publishes CAA records, NoCert reads them and compares them against the issuers it actually found.
A certificate whose issuer is not authorized by its domain’s current CAA policy is flagged in the certificate list as Unexpected issuer. That usually means a certificate was issued before the CAA record changed, or that something is issuing outside the path you intended.
The CAA chip on the row opens a drawer holding the state NoCert found: a policy that matches your issuers, one that does not, a record it could not parse, no record at all, a name it could not resolve, or nothing checked yet. Where a record is missing or incomplete the drawer offers the record you would publish to cover the issuers already seen. Re-check reads DNS again without waiting for the next cycle.
Suggested domains
Section titled “Suggested domains”A panel beside the list proposes up to five related names, drawn from what you already own and from any DNS connector you have synced. Adding one from there opens the verification dialog for you.
The names derived from your own domains need one verified domain to work from. Zones a connector found do not, so a synced connector fills the panel on an organization that has verified nothing yet.
Verification does not expire
Section titled “Verification does not expire”Removing the TXT record after a domain is verified does not un-verify it. NoCert checks the record once, on the way from Pending to Active, and never looks again.
Keep the record if it costs you nothing. If you re-add a domain later, you verify again with a fresh token.
Removing a domain
Section titled “Removing a domain”Deleting from the row menu asks you to type the domain name to confirm.
The delete stops discovery for that domain and cancels its queued scans. By default the certificates and endpoints stay: they are evidence of what you had, and other domains may share them.
Ticking Delete linked certificates removes the leaf certificates that only cover this domain, and the endpoints left serving nothing. NoCert keeps CA certificates, anything that also covers another of your domains, any endpoint still serving something or carrying one of your tags, and every entry in the activity log.
A scan already in flight can briefly re-add a certificate. A sweep about ten minutes later removes it.