Verified domains
Pentestas only scans targets you've proven you own. This page manages the list.
Add a domain
See Verify a domain for the full flow. Quick version:
Settings β Domains β Add domain β enter bare domain β follow DNS TXT / file / meta-tag instructions β click Verify.
What verification covers
A verified domain unlocks:
- The domain itself + all subdomains under it (
api.,staging., etc.). - Matching IP addresses (only when the domain's DNS resolves to the IP at scan time β no standalone IP scanning unless you set up IP allowlisting).
Bulk verify
Enterprise plans can pre-authorise many domains via:
- CSV upload β
domain,methodcolumns. - Parent domain inheritance β verifying
example.comautomatically covers anysub.example.comyou add later without re-challenge, as long as you keep the parent's TXT record live. - Proof of ownership by IP range β BGP-announced prefix match.
Remove a domain
Settings β Domains β pick domain β Remove. Immediate. Any scheduled scans against that domain will fail on their next run until re-verification.
Removal does not delete existing scan history β past scans remain readable; only new scans are blocked.
Re-verification
Pentestas periodically re-checks (every 30 days). If the TXT record / well-known file / meta tag has vanished, the domain drops to Pending re-verification. Scans against it pause until you re-publish the token.
Private / internal domains
For .corp.local, .internal, and similar non-public zones that can't have a public TXT record:
- Agent-based verification β deploy an agent in the network; the agent verifies a file on an internal host via DNS+HTTP probe from inside.
- API-based manual approval β Enterprise customers can whitelist domains that an Enterprise admin approves via written attestation.
Talk to us if you need this β it's a manual workflow, not self-serve.
See also
- Verify a domain (first time)
- Plans and limits β per-plan verified-domain caps