Platform module
External Footprint Monitoring
Keep the public technical records around your domains under review — SSL, DNS, RDAP/domain expiry, and email authentication — and pair them with the governance context your team records by hand: who owns each domain, why it exists, how its certificate renews, and which systems send mail from it. CertPilot turns both into management-ready Domain Health evidence.
See Domain Health in action
Public-signal checks with the governance context beside them.
See how a synthetic workspace keeps domain health, ownership context, and review priorities visible without turning CertPilot into a privileged scanner.
Synthetic workspace shown. Preparation and evidence organization—not certification, an audit guarantee, or legal advice.
What CertPilot checks automatically
The checks are intentionally focused on public data sources. That keeps setup simple and avoids turning a governance evidence tool into a privileged scanner. They run daily across every domain you add.
SSL and TLS
Certificate expiry, issuer, and validity are read from the public TLS handshake, so you catch certificates close to expiry or already invalid.
DNS records and changes
Public A, AAAA, MX, NS, TXT, and CAA records are tracked, and changes between checks are highlighted so you can see what moved and when.
RDAP / domain expiry
Domain registration data is read through public RDAP where available, including expiry dates and registrar context.
Email authentication
Public MX, SPF, DMARC, MTA-STS, TLS-RPT, and BIMI records are checked where applicable, so email-authentication evidence sits with the rest of the domain record.
For the exact data-source boundaries, read the CertPilot methodology.
What your team can record
Automated checks tell you the technical state. The governance context — who owns a domain, why it exists, how its certificate renews — lives in your team's head. CertPilot lets you record it as customer-entered metadata on each domain, so it sits next to the checks instead of in a separate spreadsheet.
Domain governance
- Owner — the internal person or team accountable for the domain
- Purpose — why the domain exists or what it is used for
- Lifecycle status — active, parked, redirect, decommission candidate, or retired
- Renewal decision — renew, let expire, review, or undecided
- Last reviewed date — when a human last checked the record
SSL readiness
- SSL management method — how the certificate is renewed
- SSL automation status — automated, manual, vendor-controlled, or unknown
- SSL readiness notes — validation method, vendor contact, known gotchas
- SSL reviewed date — when the renewal path was last confirmed
Email sending sources
- A register of which systems send mail from each domain
- Recorded ownership and context for each sending source
- Customer-entered metadata — no mailbox or message scanning
These fields are customer-entered and do not affect technical health scoring. The domain owner is whatever your team records — it is never derived from RDAP/WHOIS registrant data. Governance and SSL readiness metadata can be moved in and out with CSV import and export, and a review queue surfaces neutral operational counts for missing owners, undecided renewals, and domains that have never been reviewed.
Why this matters
Monitoring catches the technical problems. Governance metadata answers the questions a manager or auditor actually asks: do we know what we own, who owns it, and whether it is under deliberate control?
- Domain portfolios get messy as brands, campaigns, acquisitions, and business units add names over time.
- Nobody remembers why old domains exist, who owns them, or whether they should still be renewed.
- DNS changes need evidence you can show later — what changed and when — not just a one-time alert.
- 47-day SSL lifetimes mean more frequent renewals, which makes manual and vendor-controlled renewal paths riskier.
- Email-sending systems need recorded ownership and authentication context as senders are added and removed.
What the Domain Health Report includes
External footprint data is not just an alert stream. It becomes a single, shareable PDF that shows both the technical state and the governance context.
Technical health
SSL expiry and validity, DNS records, RDAP/domain expiry, and email-authentication signals across every domain.
DNS changes
A read-only before/after view of which public DNS records changed between checks, so changes are documented, not just noticed.
Domain Governance Review
Owner, purpose, lifecycle status, and renewal decisions summarised alongside the checks — evidence the portfolio is under deliberate management.
What this module does not do
CertPilot stays on the evidence side of the line. It checks public records, captures changes, and records governance context; it does not become a scanner, a DNS editor, or a certificate manager.
- No DNS editing, restore, or rollback — DNS evidence is read-only. CertPilot is not a DNS restore tool.
- No certificate issuing, installation, renewal, or ACME/Certbot automation. CertPilot is not a certificate automation tool.
- No mailbox, message, or header scanning — email checks read public DNS records only, never inbox contents.
- No vulnerability scanning, penetration testing, uptime monitoring, or page-speed monitoring.
- No compliance certification or audit guarantee — CertPilot produces operational evidence, not certification.
- Governance and SSL readiness fields are customer-entered metadata, do not affect technical health scoring, and are never derived from RDAP/WHOIS registrant data.
Guides
Practical, evergreen guides on the topics this module covers.
47-day SSL certificates: what IT teams need to track before 2029
The official CA/Browser Forum timeline and how to track SSL readiness per domain.
Domain governance register: what to track for every company domain
Why an inventory is not enough, and the fields that turn a domain list into decisions.
DNS change evidence across a domain portfolio
Capturing what changed and when — and the line between evidence and DNS restore.
Try the free tools
Run a public check now — no account required. These are the same signals the module monitors continuously.
Related platform pages
External footprint FAQ
Does CertPilot renew SSL certificates?
No. CertPilot is not a certificate authority or an ACME client. It monitors public SSL signals and lets your team record SSL readiness metadata. It does not issue, install, renew, or rotate certificates — that stays with the host, ACME client, CDN, or vendor that owns it today.
Does CertPilot edit or restore DNS records?
No. CertPilot reads public DNS records and shows what changed between checks. It does not edit, roll back, or restore DNS records and it does not hold DNS provider credentials. To revert a change you use your DNS provider's control panel; CertPilot's evidence shows the previous values.
Does CertPilot scan mailboxes?
No. Email-authentication checks read public DNS records (MX, SPF, DMARC, MTA-STS, TLS-RPT, BIMI) only. CertPilot does not read mailboxes, message bodies, or headers, and there is no Microsoft 365 or Google Workspace connector.
Does the governance metadata affect technical health scoring?
No. Governance and SSL readiness fields are customer-entered planning metadata, displayed alongside the automated checks. They do not change SSL, DNS, or domain-expiry scoring. Any "needs review" cue is a neutral operational prompt, not a technical pass or fail.
How does CertPilot help with 47-day SSL certificates?
Public TLS certificate lifetimes drop to a maximum of 47 days by 2029 under the CA/Browser Forum schedule. CertPilot monitors certificate expiry daily and lets you record SSL readiness metadata so you can classify each domain as automated, manual, vendor-controlled, or unknown. It helps you track readiness; it does not automate certificate renewal.
Is this only for agencies?
No. External Footprint Monitoring serves lean internal IT teams managing company domains, MSPs managing many business clients, and web agencies managing client websites. The checks and governance metadata work the same for a portfolio of company domains or a roster of client domains.