Skip to main content

Monitored domains

Umbra watches domains. A monitored domain is what every other screen hangs from. Its exposed credentials fill the Exposures table, its people get a risk posture, and a new detection against it raises an alert. The Domains screen lists the domains a workspace watches and is where more are added.

The work email domain​

The domain of the address used to sign in is authorized for the workspace with no setup step. Umbra also registers it for monitoring on its own, the first time someone opens Domains or Exposures in a workspace that has no domain yet. Those two screens are the only ones that trigger it, so a workspace whose first visit goes elsewhere is already authorized but not yet registered.

A mailbox at a consumer, ISP or disposable email provider is the exception. Holding an address there proves nothing about who controls the provider's domain, and monitoring it would match millions of unrelated people. No domain is authorized in that case and the workspace starts with nothing monitored. A provider's domain cannot be proven with the DNS check either, so the way forward is to add the domain the organization owns.

Adding another domain​

Every other domain has to be proven before it can be watched. Add domain on the Domains screen opens the dialog that does it.

  1. Enter the domain. A domain the workspace is already authorized for is added straight away and the button reads Add domain. Anything else goes through the ownership check, where the button reads Verify & add.
  2. Publish the TXT record the dialog shows at the apex of the domain. The dialog copies the value to the clipboard.
  3. Select Check & add.
FieldValue
TypeTXT
Host@
Valueumbra-domain-verification=<token>

The record sits at the apex alongside SPF and DKIM rather than replacing anything. DNS takes a few minutes to propagate, and a check that runs before the record resolves reports that it is not there yet. Checking again costs nothing.

A pending token lasts 30 days. Reopening the dialog inside that window shows the same value rather than issuing a new one. After it lapses the check reports the token as expired and verification has to be restarted, which mints a fresh value to publish. Once a domain passes, it stays verified. There is no periodic re-check.

Authorized domains that are not monitored​

A domain can be authorized without being monitored. That is the state a domain lands in after monitoring is stopped, and the state of a domain the Wazuh team grants directly. The Domains screen collects them in a banner that counts how many are ready to monitor, with one button per domain that registers it. No DNS check is repeated.

What the table reports​

Three counts sit above the table: how many domains are monitored, the alerts received across them, and how many of those are new in the last 30 days.

These count Umbra's alert log, not everything the reputation feed holds for a domain: the records the feed pushed to Umbra since the domain was registered, plus any alerts a later re-registration caught up. The domain's full exposure is on Overview and Exposures, and in the table's In the feed column.

ColumnWhat it holds
DomainThe domain being watched.
StatusActive or Paused.
Alerts receivedEvery alert Umbra has received for the domain.
New alerts (30d, by record date)Those whose own record date falls inside the last 30 days.
Last alertHow long ago the most recent alert arrived, or No alerts yet when none has.
In the feedThe reputation feed's total for the domain, the figure Overview and Exposures show, linked to Exposures. It appears at once when this tab has already loaded the domain; otherwise Check reads it on click. A + after it means part of the feed has not answered yet, so the domain holds at least that many.
AddedThe month the domain was registered.

Pointing at a row reveals the control that stops monitoring it.

A domain you are authorized to search but can never monitor, such as a public email provider like gmail.com, is listed under Search only below the counts. That is why the domain picker on the other screens can offer a domain this list does not hold.

The first run​

Registering a domain imports nothing. Its past exposures are shown live from the reputation feed on every screen, and alerts start from the day you add it. Registering a domain that is already monitored again catches up any alerts raised for it that the console has not stored yet, and reports them as a single Alerts caught up bell entry, not one entry per record.

There is no first scan to wait for. A newly registered domain reads Active straight away, with No alerts yet until its first alert arrives.

A domain that comes back with nothing found is a result, not a failure. It means the feed holds no exposed credentials for it.

Switching which domain a screen reads​

A workspace authorized for more than one domain gets a domain control on Overview, Identities, Devices, Sources and Services, and a domain selector in the header of Exposures. Each screen reads one domain at a time and the control changes which. It is hidden entirely when there is only one domain to choose, and the work email domain is the default. The Domains screen itself always lists every domain.

Switching domain on Exposures also clears the filters, so a narrowing set for the previous domain cannot quietly empty the new one.

Stopping monitoring​

The control on a table row stops monitoring that domain. It applies immediately and asks for no confirmation. Umbra de-registers the domain with the reputation feed and deletes the exposure records collected for it, so the history collected under that domain goes with it.

The proof of ownership survives. A domain that was verified stays authorized after monitoring stops, which is why it reappears among the authorized domains ready to monitor. Adding it again starts a new first run, which, like any first registration, imports nothing: alerts start again from that day.

What a plan changes​

Adding and verifying a domain works the same way on both plans. What the plan changes is what the records show once they arrive. See Plans and billing.