-
-
Notifications
You must be signed in to change notification settings - Fork 27
Domains
A register of every domain name your organisation holds - or, on an MSP install, every domain each client holds. It keeps itself up to date from the registries, checks how well each domain is protected, and tells you before anything lapses or changes.
Asked for in GitHub #154. For how it is built, see the Domains developer guide; for other systems, REST API: Domains.
| π Register | Every domain with its expiry countdown, status, registrar, owner, security grade, locks and certificate expiry. Views for the questions people actually ask - needs attention, expiring in 30 days, transfer unlocked, grade C or below. |
| π Lookups | Add a name and the registrar, registration and expiry dates, name servers and lock status are filled in from the registry. |
| π‘οΈ Security grade | A+ to F, from daily checks of DNS, email security and certificates - each finding with advice in plain English and, where it helps, the exact record to publish. |
| π¨ Change detection | Name servers, registrar, mail servers or a lock changing is recorded, and can be emailed at once - it is what a hijacked domain looks like. |
| β° Alerts | Renewal and certificate warnings as one digest per person, plus the notification bell and workflows. Can also raise a task or a ticket at the renewal window. |
| π Watches | Optional: new certificates issued for your names (Certificate Transparency), and look-alike domains registered one keystroke from yours. |
| π Connections | Each domain linked to the CMDB items that depend on it, the tickets about it, its runbooks in Knowledge and its contract - shown on both sides. (3.0.0) |
| π¦ Service Status | Link the services that run on a domain, and an expired domain or certificate flags them as at risk - or raises the incident by itself, if you choose. (3.0.0) |
| π±οΈ Right-click | Open, edit, refresh, check, set status or owner, and more, straight from the register. (3.0.0) |
- Add - one name. Paste a web address or an email address if that is easier; it is tidied into the domain name.
- Paste list - as many as you like, one per line. Duplicates are skipped and listed.
- Import CSV - a spreadsheet saved as CSV. You match its columns on screen; only the domain name is required, and status, owner and registrar are matched by name.
New domains are looked up and checked straight away, in batches with a progress bar. Anything not finished is picked up by the scheduled run.
Note
About a sixth of domain endings - mostly country codes such as .de, .io and .co - have no modern lookup service (RDAP). FreeITSM uses the older WHOIS service for those. A few registries, .de among them, never publish an expiry date; enter it from the registrar's invoice so the reminders still work.
Every domain has a Purpose: primary, secondary, redirect only, email only, defensive, parked or campaign. It changes what the checks look for. A domain that should never send email (parked, defensive, redirect) is checked for being locked down - the SPF record v=spf1 -all, a DMARC reject policy, no mail servers - because an unused, unwatched domain is exactly what a phisher wants to send from.
Each check is a pass, a note, a warning or a failure. Warnings and failures cost points from 100:
| Grade | Score |
|---|---|
| A+ | 100 |
| A | 90+ |
| B | 80+ |
| C | 65+ |
| D | 50+ |
| F | below 50, or the registration has expired / is being deleted |
The checks cover registration (expiry, transfer lock, registry lock, how it renews), DNS (name servers, DNSSEC, CAA), email (SPF including its 10-lookup limit, DKIM, DMARC, MTA-STS, TLS reporting) and certificates (the domain, www, and any sub-domains you list).
The domain page's Overview shows the three things most worth fixing; Security and email lists every check.
Tip
.uk domains move between registrars by a change of registrar tag rather than an auth code, so most have no transfer lock at all. FreeITSM does not mark them down for it, but says so, and shows the lock as on for the registrars that do offer one.
Email alerts are off until you switch them on in Domains β Settings β Alerts - press Preview first to see who would be emailed today.
- Warnings go at 60, 30, 14, 7 and 1 days before expiry by default, once per expiry date - renewing re-arms next year's.
- After a domain lapses, a reminder every 7 days for 45 days, while it can still be rescued.
- One digest per person, not one email per domain.
- Domains whose status has alerts off (Letting lapse, Cancelled) and domains set to Do not renew are left out.
- Optionally raise a task or ticket at the renewal window, assigned to the domain's owner.
- The owner's notification bell hears about expiring domains, expiring certificates and detected changes whether or not email is on - each switchable in System β Preferences.
- Workflows can trigger on any domain event.
Domains β Accounts records the accounts at registrars that hold your domains: which login, who owns it, and who holds the second factor. Never a password - keep that in your password manager.
A domain's auth code (EPP code) lets whoever holds it transfer the domain away. FreeITSM stores it encrypted, never shows it in a list or over the API, and only analysts with the auth codes permission (System β Roles) can see or change one. Every view is written to the domain's history.
One script keeps everything fresh: cron/domains.php, hourly. It refreshes registry details (weekly, and daily for anything expiring within 45 days), runs the checks daily, runs the optional watches weekly, then sends alerts, brings the Calendar up to date (domain and certificate renewals) and - as Settings β Service Status decides - raises incidents for linked services whose domain is in trouble and resolves those that have recovered. Each is recorded once done, so running it more often never repeats anything. Domains β Settings β Monitoring shows the command, a web address to call instead, and a Run now button.
Without a cron, opening Domains runs a short batch at most once an hour - enough for a small register, but nothing runs if nobody opens it.
A domain's Connections tab links it to the rest of FreeITSM. Every link shows on both sides, and can be made from either:
| Linked to | On the domain | On the other side |
|---|---|---|
| CMDB items that depend on it | what breaks if it lapses | a Domains panel on the CI's page |
| Service Status services that run on it | the services at risk (below) | β |
| Tickets about it | a list with each ticket's status | π pills in the ticket's Links strip - Link toβ¦ β Domain |
| Knowledge articles - its runbooks | how to move its DNS, renew it, who to call | listed under the article; linked in the article's editor |
| Its contract | the contract it is renewed or billed under (set in Edit) | a Domains section on the contract, with each domain's yearly cost and the total |
You only see, make or remove a link when you can open both ends: Domains and the other module, and the record itself. A CI or a ticket must be in the same company as the domain. Somebody without Domains sees no domain panel anywhere, rather than an empty one.
An expired domain - or an expired certificate - is an outage for the services that run on it. Link those services on the domain's Connections tab, then choose in Domains β Settings β Service Status what happens when the domain is in trouble:
| Setting | Choices |
|---|---|
| When a linked domain is in trouble | Do nothing Β· Suggest (the default) - the Connections tab lists the services at risk with a Raise incident button Β· Raise by itself - the scheduled run raises it |
| What counts | The domain has expired Β· its certificate has expired, optionally a number of days before it does |
| Impact on each service | Any of your impact levels; blank = the most severe level that counts as downtime |
| Publish straight away | Off by default: the incident opens with an internal update and customers see nothing until somebody writes to them |
| Resolve when the domain recovers | On by default: renew the domain or replace the certificate and the incident is closed with a resolved update |
An incident is raised once per problem: the same expiry date never raises a second, and renewing re-arms it. The Watchtower Domains card counts the services at risk.
The tab has its own permission (System β Roles), marked sensitive, because it can publish to a page customers read.
Right-click any domain in the register for: Open, Open in a new tab, Edit, Refresh lookup, Check now, Status βΊ, Owner βΊ, Assign to me, Connections, Visit website, Copy name and Delete. Each does exactly what the same action on the domain's own page does, history included.
| Where | What |
|---|---|
| Watchtower | A Domains card: expiring, certificates, unlocked, weak grades, and services at risk. Renewals and certificates each appear only if their own setting says so |
| Calendar | Two kinds, each with its own setting in Settings β Alerts: domain renewals (Where renewals are shown) and certificate renewals (Where certificate renewals are shown). Each goes in its own category, Domain renewals and Certificate renewals - rename either to your own language or wording and FreeITSM keeps filing into it, never making a second one. Switching one kind off removes only its own entries |
| CMDB, Tickets, Knowledge, Contracts | The Connections above |
| Service Status | Incidents suggested or raised for linked services |
| βK search | Domains by name, registrar or tag |
| Contracts β Suppliers | A registrar's page lists the domains it holds |
| Documents | Attach invoices and transfer authorisations to a domain |
| Workflows | Triggers for added / changed / deleted, expiring, certificate expiring, change detected, new certificate, look-alike found |
| Feature Bingo | 20 cards for the Domains features worth setting up |
Three people-fields answer three different questions, and none of them replaces another:
| Field | Who it can be | What it is for |
|---|---|---|
| Owner | One of your analysts | Who is responsible. Gets the renewal reminders, the bell notifications and any task or ticket raised at the renewal window. |
| Technical contact | One of your analysts, or a contact at a supplier (the web agency, the host) | Who looks after the DNS and hosting. One or the other, never both. (Analysts added in 3.1.0, #162.) |
| Customer | A person from Users in the domain's own company, or a supplier, optionally with one of its contacts | Who you look after the domain for. A person or a supplier, never both. (Suppliers added in 3.1.0, #162.) |
Both are set in the Edit dialog. The technical contact is one list with Analysts and Supplier contacts groups. The customer is one search box: type two letters and it offers People (in the domain's company) and Suppliers and contacts together. Pick a contact and their supplier comes with them. On the domain's page each name links to its People page β a person's, a supplier's or a contact's β and that page lists every domain they are named on.
If you only manage your own domains, leave Customer empty and nothing is different. If you manage domains for customers, the customer can be one of your users or an organisation you keep in Contracts β Suppliers, whichever fits how you record them. See also Contracts with customers.
Works on a phone: the register's views and filters live behind a Filters button, and the list, accounts and a domain's page are laid out for a narrow screen - see Mobile: Domains.
On a multi-company install each domain belongs to one company; see the help page's Companies section. Calendar entries have no company, so domain and certificate dates in the Calendar are visible to everyone who can open it. Connections keep to the company too: a CMDB item or ticket can only be linked to a domain in the same company (Service Status services and knowledge articles are not company records).
Connections are not in the REST API yet - they are made and read on the screens.
FreeITSM β an open-source IT Service Management platform Β· github.com/edmozley/freeitsm Β· MIT licence
- Installation
- β° Scheduled tasks (cron jobs)
- Architecture
- π§ͺ Developer tests
- AI Providers
- Internationalisation (i18n)
- Timezones & Time Handling
- π Date & Time Formats
- Theming & Dark Mode
- ποΈ Recent β getting back to what you were doing
- β¨οΈ Command palette (βK)
- π Searching inside tickets
- π Attached documents
-
MobileβFriendly
- β³ π« Mobile: Tickets
- β³ π» Mobile: Assets
- β³ π Mobile: Calendar
- β³ π Mobile: Knowledge
- β³ π¦ Mobile: Service Status
- β³ πΌ Mobile: Watchtower
- β³ π§© Mobile: Problem Management
- β³ π Mobile: Change Management
- β³ πΏ Mobile: Software
- β³ β Mobile: Tasks
- β³ π Mobile: Forms
- β³ π Mobile: Contracts
- β³ π Mobile: Domains
- β³ π Mobile: People
- β³ π Mobile: LMS
- β³ πΊοΈ Mobile: CMDB
- β³ πΊοΈ Mobile: Network Mapper
- β³ π§ Mobile: Process Mapper
- β³ βοΈ Mobile: Workflow
- β³ π₯οΈ Mobile: System
- β³ π Mobile: Reporting
- β³ π Mobile: System Wiki
- β³ π Mobile: Self-Service Portal
- β³ π§° Mobile: Techniques & Tricks
-
Security
- Layer 1 β which modules you can enter
- β³ π§© Module Access Control
- β³ π οΈ Module Access β Developer Guide
- Layer 2 β what you can administer
- β³ π Roles & Permissions
- β³ π οΈ Roles β Developer Guide
- β³ π€ Why capabilities are constants
- Layer 3 β the System module
- β³ π Admin Access Control
- Hardening
- β³ π Security review response 2026-08
- β³ π‘οΈ Security hardening 2026-08
- β³ π οΈ Security hardening 2026-08 β Developer Guide
- β³ π‘οΈ Round three β plain English
- β³ π οΈ Round three β Developer Guide
- β³ π‘οΈ CSRF protection (S4) β Developer Guide
- Single Sign-On (SSO)
- ποΈ LDAP & Active Directory
- π CardDAV contact sync
- Browser Extension
- API Reference
-
π REST API β how it works
- β³ π« REST API: Tickets
- β³ π» REST API: Assets
- β³ π΄ REST API: Problems
- β³ π REST API: Changes
- β³ π REST API: Knowledge
- β³ β REST API: Tasks
- β³ ποΈ REST API: CMDB
- β³ π REST API: Contracts
- β³ ποΈ REST API: Calendar
- β³ πΏ REST API: Software
- β³ π REST API: Domains
- β³ π¦ REST API: Service Status
- β³ βοΈ REST API: Morning Checks
- β³ π REST API: Forms
- β³ βοΈ REST API: Workflow
- β³ π·οΈ REST API: Cost centres
- β³ πΊοΈ REST API: Network Mapper
- β³ π§ Using the API docs page
- β³ π OpenAPI specification
- β³ β OpenAPI: kept correct
- β³ π οΈ Maintaining the catalogue
- Watchtower
-
Tickets
- β³ π Rota copy and paste β Developer Deep Dive
- β³ β Checklists & SOPs
- β³ βοΈ Mandatory fields
- β³ π·οΈ Ticket categories
- β³ π₯ Assigning tickets to a team, and escalation
- β³ π’ One board across every company
- β³ Mailbox Authentication
- β³ π€ Email send log
- β³ Basic IMAP mailboxes
- β³ Email rendering & images
- β³ SLA Management
- β³ WhatsApp channel
-
β³
βοΈ Telegram channel - β³ β CSAT company scope and filters β Developer Guide
- β³ π₯ Microsoft Teams channel
- β³ π¨οΈ Mattermost channel
- β³ π¬ Web chat channel
- β³ π£ Slack channel
- β³ π Linking tickets
- β³ β Record previews
- β³ π Ticket notes: internal or shared
- β³ ποΈ Canned responses
- β³ βοΈ Limiting replies to particular senders
- β³ π¨ Telling the analyst a ticket is theirs
- β³ βοΈ Email signatures
- β³ π The public web address
- β³ π’ Ticket numbering
- β³ π Raising a ticket for someone else
- β³ π Merging tickets
- β³ π Confidential tickets
- β³ π₯ Portal managers
- β³ π Who has seen a ticket
- β³ π Reading long tickets
- β³ β Splitting tickets
- β³ β Selecting several tickets
- β³ ποΈ The folder pane
- β³ π½ Just my tickets, or no closed ones
- β³ π οΈ Snoozing tickets β Developer Guide
- β³ π₯ Collision detection
- β³ β±οΈ Time tracking
- β³ π Scheduled work in your own calendar
- Problem Management
- Tasks
-
Assets
- β³ π’ Moving an asset between companies
- β³ π Shared asset locations
- β³ π§βπΌ Assigning assets to analysts
- β³ π Warranty and lease alerts
- β³ π Saved table views
- β³ π¨οΈ Recording anything, and importing it
- β³ π·οΈ QR asset labels
- β³ π Who holds what, and handover documents
- β³ π₯οΈ The inventory agent (PowerShell)
- β³ ποΈ Proxmox VE servers
- β³ βοΈ VMware Cloud Director servers
- β³ π Linking equipment to tickets
- β³ βοΈ Follow-up tasks on a ticket
- Knowledge
- Change Management
- Calendar
- Morning Checks
- Reporting
- Software
-
Forms
- β³ π¨ The form designer β Developer Guide
- β³ π Layout & the grid β Developer Guide
- β³ ποΈ Collections β grouping submissions
- β³ π Submissions as PDFs
- β³ β‘ What happens next β a form's own actions
- β³ π οΈ Sections & conditional logic β Developer Guide
- β³ π οΈ Lookup fields β Developer Guide
- β³ π‘οΈ Catalogue request approvals
- People
- Domains
- Contracts
- Service Status
- π Notifications
- π¨ War Room
- Self-Service Portal
- LMS
- Process Mapper
- CMDB
- Network Mapper
- Workflows
- Issue trackers (Jira, Azure DevOps)
- System
-
Overview
- β³ π Progress tracker
- β³ Concepts & vocabulary
- β³ Email routing & mailboxes
- β³ Settings: global vs per-company
- β³ Users & self-service
- β³ Staff cross-company access
- β³ π’ One board across every company
- β³ Worked examples
- β³ Pitfalls & gotchas
- β³ Scope: what it's for
- β³ π οΈ Developer Guide (make a module multi-company)
- β³ ποΈ Case study: CMDB (a linked graph)
- β³ π§ͺ Test harness (prove it's isolated)
- What this is
-
π Bugs resolved
- β³ π’ Chat tickets ignored your ticket numbering
- β³ π Dates shown as a dash, or in server time
- β³ π Assets β Users showed people from other companies
- β³ π Restricted analysts could read other modules' data
- β³ πΌοΈ Replies with a picture in the thread failed to send
- β³ π Reply attachments never reached the customer
- β³ π οΈ Outbound email attachments β Developer Guide
- β³ π A global SSO provider was missing from the portal
- β³ π Behind a proxy, the SSO redirect said http
- β³ βοΈ The portal tagline moved when you saved it
- β³ π¨ The portal settings screen forgot what you saved
- β³ π‘οΈ The approvals inbox said "Error" and nothing else
- β³ π A table's answers were missing from the PDF
- β³ β A single-select column let you tick every option
- β³ π The portal ignored a form's field widths
- β³ π The tasks board stopped taking clicks
- β³ ποΈ #121 The index list is out of date after upgrading
- β³ π #133 The calendar subscription was empty
- β³ π #131 Tasks always reopened on the board
- β³ π₯ #129 Every page returned HTTP 500 after upgrading
- β³ π³ #127 A PHP warning above the System page
- β³ π #126 Notes stamped with the server's clock
- β³ π Storing every date in UTC
- β³ πͺ The portal was down for everyone signed in
- β³ βοΈ #120 Workflow notes could never be written
- β³ βοΈ #123 Three errors when running Database Verification
- β³ π #122 The description box was a stub in the corner
- β³ π£ Demo data deleted real accounts
- β³ π #117 Sign-in redirected to the wrong address
- β³ π¨ #108 The priority dot was invisible
- β³ β±οΈ #116 Time logged from the right-click menu
- β³ π #114 API keys refused by our own guard
- β³ ποΈ #110 Assigning a task told nobody
- β³ πͺ #107 Signed out while still working
- β³ π #103 "Share with Requester" reached nobody
- β³ π #102 Search found nothing for hyphens
- β³ πͺ #101 Source code editor opened behind
- β³ βοΈ #88 Subtasks could not be ticked off
- β³ π» #84 Asset deep link selected nothing
- β³ π« #79 A new ticket arrived with no status
- β³ π§ #79 A ticket from email did not say so
- β³ π #78 Bell opened to nothing
- β³ π¬ #77 Mail only collected from Inbox
- β³ π #74 The default password could not be changed
- β³ π¦ #70 Renaming an impact level
- β³ π€ #67 App-only mailboxes could not send
- β³ π #45 Verify only ever worked for Microsoft
- β³ π #45 IMAP reported as not authenticated
- β³ βοΈ An email template stopped escaping itself
- β³ π The portal dashboard showed the wrong time
- β³ π’ The folder said 99 and the list showed 96