1. Add a domain
Sign up (the 7-day trial needs no card), open Domains and add the
registrable domain, for example example.com. Verifying the registrable domain covers
every host under it: www.example.com, api.example.com and anything discovered
later. You can also save specific subdomains to monitor from day one.
2. Prove you control it
Any one of four proofs is enough. The app shows the exact values to use for your domain.
| Method | What you do | Best when |
|---|---|---|
| DNS TXT record | Publish the token we issue (it looks like afs-site-verification=…) as a TXT record at _afs-verify.example.com. | You can edit DNS. The most durable proof. |
| Well-known file | Serve the token as a line of https://example.com/.well-known/afs-verify.txt. HTTPS is tried first; plain HTTP is accepted as a fallback. | You can deploy to the website but not change DNS. |
| Work email | If the email you signed in with is a verified mailbox at the domain (not a shared provider such as gmail.com), the domain verifies with nothing to publish. | You are the domain's own IT or security team. |
| Emailed approval | Name a mailbox at the domain. We email it, and the person there approves or refuses monitoring from a page of their own. | An MSP or consultant working for the domain's owner. |
Press Verify after publishing. DNS changes can take a few minutes to become visible; the app tells you what it found if the check fails (for example a TXT record that exists but holds a different value).
Domains verified by DNS record or file are re-checked every night. If the record or file disappears, the domain is demoted and scanning stops until it is re-verified. This is deliberate: authorization should not outlive the evidence for it. Domains verified by work email or emailed approval are not re-checked automatically.
3. First scan and schedule
The first scan starts as soon as the domain verifies and usually finishes in about a minute. After that, scheduled scans run weekly on Starter and daily on Growth and above, certificate transparency is read every 15 minutes on every plan, and the certificate each host serves is re-checked daily (Starter) or every 6 hours (Growth and above). Manual scans are available any time within your plan's monthly allowance.
A first scan never produces "changes": it is the baseline. Changes start with the second scan, so the feed stays meaningful.
4. Hosts under the domain
The monitored set for a domain is the apex, the subdomains you save, and the subdomains discovery finds, minus anything on the domain's exclusion list, capped by your plan's hosts per domain (20 on Starter, 100 on Growth, 250 on MSP, 1,000 on Enterprise). Removing a host adds it to the exclusion list so discovery does not add it back. See Asset inventory & discovery.
5. Decide where alerts go
Critical changes are sent the moment they are found; everything else goes into a weekly digest (skipped when nothing changed). Add an email address, Slack, Microsoft Teams, PagerDuty, Jira or a webhook under Notifications. See Integrations.
6. Invite your team
Invite colleagues from Team. Invitations are matched by email address the first time that person signs in, so nothing is lost to a spam folder. Seats range from 2 (Starter) to 25 (MSP), unlimited on Enterprise.