Skip to main content

Discovery and scan coverage

Learn why a hostname may be missing, why an old name still appears, and what an external scan cannot see.

On this page

Use SSLBoard as an inventory of discovered and inspected public services. Compare that inventory with your own DNS and hosting records before calling it complete.

Why old or unfamiliar names appear

Certificate-based discovery can retain names associated with earlier deployments. A name might now fail DNS resolution, resolve to a private address, or point to a retired service. This is useful cleanup evidence, but it is not proof that a forgotten public server is still running.

A certificate can also contain names used by a shared hosting service or another organization. The adjacent domains section describes those certificate relationships without claiming common ownership.

Why a name can be missing

A service may use a private certificate authority, sit behind a private network, or have no individually logged certificate name. Discovery also depends on available data and scan limits. The current hostname discovery request is capped at 20,000 names; larger inventories should not be assumed complete.

Wildcard certificates are another common source of confusion. Knowing about *.example.com does not reveal whether payroll.example.com exists. Discovery does not amount to exhaustive DNS enumeration.

Which infrastructure the evidence describes

Read the address and port in the report before assigning a finding. A hostname can resolve to multiple addresses, including IPv4 and IPv6, and their TLS settings can differ. A CDN or reverse proxy may terminate the public TLS connection, so its certificate and settings are what an outside scan sees. The connection between that proxy and your origin needs its own assessment.

The standard web target port is 443, with HTTP redirect checks on port 80. MX hosts are normally assessed separately for email, so an MX hostname can be absent from the web inventory even if it also hosts a website. The submitted hostname remains in web scope. SSLBoard does not provide an exhaustive all-port inventory, authenticated application assessment, or inspection of private-address services. Email results distinguish mail delivery from submission services; email transport explains that scope.

Freshness and retesting

A report describes observations recorded for that scan. Opening its link does not refresh the observations. Submitting the same domain can reuse an active scan or return a recent report, so check its date before using it to verify a change.

For remediation, use the report’s retest action and confirm that the resulting report is newer than the deployment you changed. See fixing and retesting.

Try these checks on your own domain: Start a free scan. If a result needs a closer look, contact us.