Domains and scanning
Domain states
Reference for domain and asset verification states.
- Audience
- All workspace members
- Plan availability
- All plans
- Last reviewed
Cyber Health Score tracks each domain or asset through ownership, verification, and lifecycle states. The labels you see in the workspace reflect the underlying model used for scanning and reporting.
Ownership type
When you add an asset, you choose how it is monitored:
| Type | Meaning |
|---|---|
| Owned | A domain your organisation controls. DNS TXT ownership verification is required before full posture scans can run. |
| Supplier monitored | A supplier or third-party domain monitored with read-only checks. DNS ownership verification is not required for this workflow, and full owned-domain scanning is not enabled here. |
Asset lifecycle status
Each asset has a lifecycle status shown in the product:
| Status | Meaning |
|---|---|
| Awaiting verification | The asset is registered but not yet ready for owned-domain scanning workflows. |
| Active | The asset is active in your workspace and may be eligible for scanning when other requirements are met. |
| Suspended | The asset is temporarily suspended and is not eligible for new scans until it is active again. |
| Retired | The asset is retired from active use in your workspace. |
If an asset has been removed from your workspace, scanning is blocked with the message that the asset is no longer available for scanning.
DNS ownership verification
For Owned assets, verification proves you control the domain before sensitive scans run. Verification records move through these states:
| Status | Meaning |
|---|---|
| Pending | A verification token has been issued and CHS is waiting for the DNS TXT record to be published or checked. |
| Verified | Ownership verification is complete. The domain is authorised for safe scanning and follow-up posture checks. |
| Failed | CHS could not find the verification token in DNS yet. Check the record name and value, wait for DNS to propagate, then verify again. |
| Expired | The previous verification token has expired. Generate a fresh token, update DNS, then verify again. |
The asset page guides you through the current step, such as generating a token, publishing the TXT record, or verifying ownership.
Scan eligibility
An asset can be queued for scanning only when all of the following are true:
- the asset has not been removed from the workspace
- the asset status is Active
- for Owned assets, ownership verification is complete (authorised)
- for Supplier monitored assets, verification is not required
If scanning is blocked, the product shows one of these messages:
- This asset is no longer available for scanning.
- This asset must be active before scanning.
- Complete domain ownership verification before scanning this asset.
Safe recovery actions
| Situation | Recommended action |
|---|---|
| Owned asset awaiting verification | Follow the DNS TXT steps on the asset page, then verify ownership |
| Verification failed or expired | Check DNS, wait for propagation, generate a fresh token if needed |
| Asset suspended | Confirm why it was suspended, restore to Active if appropriate |
| Scan button unavailable | Confirm asset status, ownership type, and verification before retrying |
| Asset retired or removed | Add or restore the asset if you still need posture coverage |
Related documentation
Related documentation
Return to the documentation home to browse all topics.
Back to documentation