Cyber Health Score

Domains and scanning

Domain states

Reference for domain and asset verification states.

Audience
All workspace members
Plan availability
All plans
Last reviewed

Cyber Health Score tracks each domain or asset through ownership, verification, and lifecycle states. The labels you see in the workspace reflect the underlying model used for scanning and reporting.

Ownership type

When you add an asset, you choose how it is monitored:

TypeMeaning
OwnedA domain your organisation controls. DNS TXT ownership verification is required before full posture scans can run.
Supplier monitoredA supplier or third-party domain monitored with read-only checks. DNS ownership verification is not required for this workflow, and full owned-domain scanning is not enabled here.

Asset lifecycle status

Each asset has a lifecycle status shown in the product:

StatusMeaning
Awaiting verificationThe asset is registered but not yet ready for owned-domain scanning workflows.
ActiveThe asset is active in your workspace and may be eligible for scanning when other requirements are met.
SuspendedThe asset is temporarily suspended and is not eligible for new scans until it is active again.
RetiredThe asset is retired from active use in your workspace.

If an asset has been removed from your workspace, scanning is blocked with the message that the asset is no longer available for scanning.

DNS ownership verification

For Owned assets, verification proves you control the domain before sensitive scans run. Verification records move through these states:

StatusMeaning
PendingA verification token has been issued and CHS is waiting for the DNS TXT record to be published or checked.
VerifiedOwnership verification is complete. The domain is authorised for safe scanning and follow-up posture checks.
FailedCHS could not find the verification token in DNS yet. Check the record name and value, wait for DNS to propagate, then verify again.
ExpiredThe previous verification token has expired. Generate a fresh token, update DNS, then verify again.

The asset page guides you through the current step, such as generating a token, publishing the TXT record, or verifying ownership.

Scan eligibility

An asset can be queued for scanning only when all of the following are true:

  • the asset has not been removed from the workspace
  • the asset status is Active
  • for Owned assets, ownership verification is complete (authorised)
  • for Supplier monitored assets, verification is not required

If scanning is blocked, the product shows one of these messages:

  • This asset is no longer available for scanning.
  • This asset must be active before scanning.
  • Complete domain ownership verification before scanning this asset.

Safe recovery actions

SituationRecommended action
Owned asset awaiting verificationFollow the DNS TXT steps on the asset page, then verify ownership
Verification failed or expiredCheck DNS, wait for propagation, generate a fresh token if needed
Asset suspendedConfirm why it was suspended, restore to Active if appropriate
Scan button unavailableConfirm asset status, ownership type, and verification before retrying
Asset retired or removedAdd or restore the asset if you still need posture coverage

Return to the documentation home to browse all topics.

Back to documentation