Add the domains you monitor
Umbra monitors domains. A monitored domain is continuously watched against the reputation feed: its exposed credentials populate the Exposures table, and new detections raise alerts.
Your own domain — automatic
The domain of the work email you signed in with is authorized automatically and registered for monitoring the first time you use the console. Nothing to configure: by the time you open Exposures, the first scan is already underway.
Additional domains — prove ownership
To monitor any other domain — a second brand, a subsidiary, a regional TLD — prove you own it with a DNS-TXT challenge from Domains → Add domain:
- Enter the domain. Umbra mints a TXT record value of the form
umbra-domain-verification=…. - Add that TXT record at the domain's apex in your DNS.
- Click Check. Once the record resolves, the domain is authorized permanently and monitoring starts.
Domains you are already authorized for but not currently monitoring — for example one granted by the Umbra team, or one you removed earlier — surface in an "authorized domains ready to monitor" banner on the Domains screen with a one-click add; no DNS check needed there.
How many domains you can monitor is a plan entitlement: 1 on Free, 10 on Pro. See Plans and billing.
The first scan
Registering a domain triggers a retrospective import: everything the reputation feed already holds for that domain, delivered asynchronously — usually within minutes. Until it lands, the Overview and Exposures screens show a "first scan in progress" state and refresh themselves every ~20 seconds.
If the scan window (about 30 minutes) passes with no findings, the screens settle into a real — and celebrated — "No exposed credentials found". A zero is a result, not an error.
Switching domains
When your tenant is authorized for more than one domain, a Domain switcher in the Exposures header changes which domain the view searches. The default is your own email domain.