πŸ›‘ Pentestas β€Ί help

Verified domains

Pentestas only scans targets you've proven you own. This page manages the list.

Add a domain

See Verify a domain for the full flow. Quick version:

Settings β†’ Domains β†’ Add domain β†’ enter bare domain β†’ follow DNS TXT / file / meta-tag instructions β†’ click Verify.

What verification covers

A verified domain unlocks:

  • The domain itself + all subdomains under it (api., staging., etc.).
  • Matching IP addresses (only when the domain's DNS resolves to the IP at scan time β€” no standalone IP scanning unless you set up IP allowlisting).

Bulk verify

Enterprise plans can pre-authorise many domains via:

  • CSV upload β€” domain,method columns.
  • Parent domain inheritance β€” verifying example.com automatically covers any sub.example.com you add later without re-challenge, as long as you keep the parent's TXT record live.
  • Proof of ownership by IP range β€” BGP-announced prefix match.

Remove a domain

Settings β†’ Domains β†’ pick domain β†’ Remove. Immediate. Any scheduled scans against that domain will fail on their next run until re-verification.

Removal does not delete existing scan history β€” past scans remain readable; only new scans are blocked.

Re-verification

Pentestas periodically re-checks (every 30 days). If the TXT record / well-known file / meta tag has vanished, the domain drops to Pending re-verification. Scans against it pause until you re-publish the token.

Private / internal domains

For .corp.local, .internal, and similar non-public zones that can't have a public TXT record:

  • Agent-based verification β€” deploy an agent in the network; the agent verifies a file on an internal host via DNS+HTTP probe from inside.
  • API-based manual approval β€” Enterprise customers can whitelist domains that an Enterprise admin approves via written attestation.

Talk to us if you need this β€” it's a manual workflow, not self-serve.

See also