Skip to content

Domains

Ed Mozley edited this page Oct 4, 2026 · 6 revisions

🌐 Domains

A register of every domain name your organisation holds - or, on an MSP install, every domain each client holds. It keeps itself up to date from the registries, checks how well each domain is protected, and tells you before anything lapses or changes.

Asked for in GitHub #154. For how it is built, see the Domains developer guide; for other systems, REST API: Domains.


What it does, in one screen

πŸ“‹ Register Every domain with its expiry countdown, status, registrar, owner, security grade, locks and certificate expiry. Views for the questions people actually ask - needs attention, expiring in 30 days, transfer unlocked, grade C or below.
πŸ”Ž Lookups Add a name and the registrar, registration and expiry dates, name servers and lock status are filled in from the registry.
πŸ›‘οΈ Security grade A+ to F, from daily checks of DNS, email security and certificates - each finding with advice in plain English and, where it helps, the exact record to publish.
🚨 Change detection Name servers, registrar, mail servers or a lock changing is recorded, and can be emailed at once - it is what a hijacked domain looks like.
⏰ Alerts Renewal and certificate warnings as one digest per person, plus the notification bell and workflows. Can also raise a task or a ticket at the renewal window.
πŸ‘€ Watches Optional: new certificates issued for your names (Certificate Transparency), and look-alike domains registered one keystroke from yours.
πŸ”— Connections Each domain linked to the CMDB items that depend on it, the tickets about it, its runbooks in Knowledge and its contract - shown on both sides. (3.0.0)
🚦 Service Status Link the services that run on a domain, and an expired domain or certificate flags them as at risk - or raises the incident by itself, if you choose. (3.0.0)
πŸ–±οΈ Right-click Open, edit, refresh, check, set status or owner, and more, straight from the register. (3.0.0)

Adding domains

  • Add - one name. Paste a web address or an email address if that is easier; it is tidied into the domain name.
  • Paste list - as many as you like, one per line. Duplicates are skipped and listed.
  • Import CSV - a spreadsheet saved as CSV. You match its columns on screen; only the domain name is required, and status, owner and registrar are matched by name.

New domains are looked up and checked straight away, in batches with a progress bar. Anything not finished is picked up by the scheduled run.

Note

About a sixth of domain endings - mostly country codes such as .de, .io and .co - have no modern lookup service (RDAP). FreeITSM uses the older WHOIS service for those. A few registries, .de among them, never publish an expiry date; enter it from the registrar's invoice so the reminders still work.

Purpose matters

Every domain has a Purpose: primary, secondary, redirect only, email only, defensive, parked or campaign. It changes what the checks look for. A domain that should never send email (parked, defensive, redirect) is checked for being locked down - the SPF record v=spf1 -all, a DMARC reject policy, no mail servers - because an unused, unwatched domain is exactly what a phisher wants to send from.


The security grade

Each check is a pass, a note, a warning or a failure. Warnings and failures cost points from 100:

Grade Score
A+ 100
A 90+
B 80+
C 65+
D 50+
F below 50, or the registration has expired / is being deleted

The checks cover registration (expiry, transfer lock, registry lock, how it renews), DNS (name servers, DNSSEC, CAA), email (SPF including its 10-lookup limit, DKIM, DMARC, MTA-STS, TLS reporting) and certificates (the domain, www, and any sub-domains you list).

The domain page's Overview shows the three things most worth fixing; Security and email lists every check.

Tip

.uk domains move between registrars by a change of registrar tag rather than an auth code, so most have no transfer lock at all. FreeITSM does not mark them down for it, but says so, and shows the lock as on for the registrars that do offer one.


Alerts

Email alerts are off until you switch them on in Domains β†’ Settings β†’ Alerts - press Preview first to see who would be emailed today.

  • Warnings go at 60, 30, 14, 7 and 1 days before expiry by default, once per expiry date - renewing re-arms next year's.
  • After a domain lapses, a reminder every 7 days for 45 days, while it can still be rescued.
  • One digest per person, not one email per domain.
  • Domains whose status has alerts off (Letting lapse, Cancelled) and domains set to Do not renew are left out.
  • Optionally raise a task or ticket at the renewal window, assigned to the domain's owner.
  • The owner's notification bell hears about expiring domains, expiring certificates and detected changes whether or not email is on - each switchable in System β†’ Preferences.
  • Workflows can trigger on any domain event.

Accounts and auth codes

Domains β†’ Accounts records the accounts at registrars that hold your domains: which login, who owns it, and who holds the second factor. Never a password - keep that in your password manager.

A domain's auth code (EPP code) lets whoever holds it transfer the domain away. FreeITSM stores it encrypted, never shows it in a list or over the API, and only analysts with the auth codes permission (System β†’ Roles) can see or change one. Every view is written to the domain's history.


The schedule

One script keeps everything fresh: cron/domains.php, hourly. It refreshes registry details (weekly, and daily for anything expiring within 45 days), runs the checks daily, runs the optional watches weekly, then sends alerts, brings the Calendar up to date (domain and certificate renewals) and - as Settings β†’ Service Status decides - raises incidents for linked services whose domain is in trouble and resolves those that have recovered. Each is recorded once done, so running it more often never repeats anything. Domains β†’ Settings β†’ Monitoring shows the command, a web address to call instead, and a Run now button.

Without a cron, opening Domains runs a short batch at most once an hour - enough for a small register, but nothing runs if nobody opens it.


Connections (3.0.0)

A domain's Connections tab links it to the rest of FreeITSM. Every link shows on both sides, and can be made from either:

Linked to On the domain On the other side
CMDB items that depend on it what breaks if it lapses a Domains panel on the CI's page
Service Status services that run on it the services at risk (below) β€”
Tickets about it a list with each ticket's status 🌐 pills in the ticket's Links strip - Link to… β†’ Domain
Knowledge articles - its runbooks how to move its DNS, renew it, who to call listed under the article; linked in the article's editor
Its contract the contract it is renewed or billed under (set in Edit) a Domains section on the contract, with each domain's yearly cost and the total

You only see, make or remove a link when you can open both ends: Domains and the other module, and the record itself. A CI or a ticket must be in the same company as the domain. Somebody without Domains sees no domain panel anywhere, rather than an empty one.

Service Status (3.0.0)

An expired domain - or an expired certificate - is an outage for the services that run on it. Link those services on the domain's Connections tab, then choose in Domains β†’ Settings β†’ Service Status what happens when the domain is in trouble:

Setting Choices
When a linked domain is in trouble Do nothing Β· Suggest (the default) - the Connections tab lists the services at risk with a Raise incident button Β· Raise by itself - the scheduled run raises it
What counts The domain has expired Β· its certificate has expired, optionally a number of days before it does
Impact on each service Any of your impact levels; blank = the most severe level that counts as downtime
Publish straight away Off by default: the incident opens with an internal update and customers see nothing until somebody writes to them
Resolve when the domain recovers On by default: renew the domain or replace the certificate and the incident is closed with a resolved update

An incident is raised once per problem: the same expiry date never raises a second, and renewing re-arms it. The Watchtower Domains card counts the services at risk.

The tab has its own permission (System β†’ Roles), marked sensitive, because it can publish to a page customers read.

Right-click (3.0.0)

Right-click any domain in the register for: Open, Open in a new tab, Edit, Refresh lookup, Check now, Status β€Ί, Owner β€Ί, Assign to me, Connections, Visit website, Copy name and Delete. Each does exactly what the same action on the domain's own page does, history included.


Where Domains appears elsewhere

Where What
Watchtower A Domains card: expiring, certificates, unlocked, weak grades, and services at risk. Renewals and certificates each appear only if their own setting says so
Calendar Two kinds, each with its own setting in Settings β†’ Alerts: domain renewals (Where renewals are shown) and certificate renewals (Where certificate renewals are shown). Each goes in its own category, Domain renewals and Certificate renewals - rename either to your own language or wording and FreeITSM keeps filing into it, never making a second one. Switching one kind off removes only its own entries
CMDB, Tickets, Knowledge, Contracts The Connections above
Service Status Incidents suggested or raised for linked services
⌘K search Domains by name, registrar or tag
Contracts β†’ Suppliers A registrar's page lists the domains it holds
Documents Attach invoices and transfer authorisations to a domain
Workflows Triggers for added / changed / deleted, expiring, certificate expiring, change detected, new certificate, look-alike found
Feature Bingo 20 cards for the Domains features worth setting up

Owner, technical contact and customer

Three people-fields answer three different questions, and none of them replaces another:

Field Who it can be What it is for
Owner One of your analysts Who is responsible. Gets the renewal reminders, the bell notifications and any task or ticket raised at the renewal window.
Technical contact One of your analysts, or a contact at a supplier (the web agency, the host) Who looks after the DNS and hosting. One or the other, never both. (Analysts added in 3.1.0, #162.)
Customer A person from Users in the domain's own company, or a supplier, optionally with one of its contacts Who you look after the domain for. A person or a supplier, never both. (Suppliers added in 3.1.0, #162.)

Both are set in the Edit dialog. The technical contact is one list with Analysts and Supplier contacts groups. The customer is one search box: type two letters and it offers People (in the domain's company) and Suppliers and contacts together. Pick a contact and their supplier comes with them. On the domain's page each name links to its People page β€” a person's, a supplier's or a contact's β€” and that page lists every domain they are named on.

If you only manage your own domains, leave Customer empty and nothing is different. If you manage domains for customers, the customer can be one of your users or an organisation you keep in Contracts β†’ Suppliers, whichever fits how you record them. See also Contracts with customers.

Works on a phone: the register's views and filters live behind a Filters button, and the list, accounts and a domain's page are laid out for a narrow screen - see Mobile: Domains.

On a multi-company install each domain belongs to one company; see the help page's Companies section. Calendar entries have no company, so domain and certificate dates in the Calendar are visible to everyone who can open it. Connections keep to the company too: a CMDB item or ticket can only be linked to a domain in the same company (Service Status services and knowledge articles are not company records).

Connections are not in the REST API yet - they are made and read on the screens.

FreeITSM

Getting Started

Modules

Multi-tenancy (planned)

Blue sky thinking

Bugs resolved

Links

Clone this wiki locally