Help center
Troubleshooting
The messages you are most likely to meet and what each means: needs an account, ownership proof, over the allowance, scan limits, 401 and 402, missing push.
Updated · 8 articles
Most "errors" in DomainGuard are the server saying exactly what it needs. This category collects the messages, what each means, and the shortest fix.
Articles
- "Needs an account" and "Ownership proof needed"
- No DMARC reports are arriving
- A domain says "on demand" or "past your plan limit"
- Scan limit reached
- API and MCP: 401, 402, 403, 429, or a missing tool
- Push notifications are not arriving
- The certificate reading looks wrong
- The lookalike check found nothing
When it is not one of these
Use Ask for help from any dashboard page or the app's Account tab. The request carries the section, the domain, your plan and any scan or error id, so the reply can be specific. Operational failures are recorded on our side with the same ids; quoting one gets you to the answer fastest.
The pattern behind most of them
Three kinds of refusal cover nearly every message in the product:
- A gate. The action needs a session, a plan, a scope, or proof of ownership. The message names which, and the API returns 401, 402 or 403 with the reason. Nothing is broken; something is required.
- An allowance. The action is metered and the window has not reset. The message names the reset time, and the API returns 429 with
Retry-After. Existing results stay readable. - A measurement. The product is reporting something you did not expect: a certificate from the logs rather than the host, a lookalike that scored benign, a domain that reads "on demand". The article explains what was measured and why.
If a message fits none of those, it is probably a bug, and the ids attached to Ask for help are how it gets found.
Where the record is
The alert feed is the record of what you were told and how it was delivered. History (Alerts tab, or GET /api/notifications/activity) is the ledger of everything the account did. A domain's History module shows every scan. When something looks wrong, those three views answer "what actually happened" before anyone guesses.
In reading order
Articles in Troubleshooting
- "Needs an account" and "Ownership proof needed"The two gates on scanning: a session for any server-side check, and account-level ownership proof for anything that probes. What each message means and the fix.Updated
- No DMARC reports are arrivingWhy a DMARC setup can look finished and receive nothing: the rua= address, the record location, a provider wizard, the 48-hour wait, and what to check in order.Updated
- A domain says "on demand" or "past your plan limit"What happens to a domain over the plan's automated allowance: it stays, it scans when you ask, it accepts edits, and the oldest domains keep the automation.Updated
- Scan limit reachedEvery manual scan is metered per plan: the allowances for website, vulnerability and dark web scans, AI refreshes, audits and probes, and the reset message.Updated
- API and MCP: 401, 402, 403, 429, or a missing toolWhat each response means when a key or an MCP client is refused, and the one fix that usually applies: mint a key with the right scope on the right plan.Updated
- Push notifications are not arrivingThe checklist for missing push: permission, device registration, the switch for that alert type, quiet hours, Focus modes, and what to tell support.Updated
- The certificate reading looks wrongWhy the certificate module can disagree with your host: logs record issuance not presentation, the app's own handshake, auto-renewing issuers, subdomain certs.Updated
- The lookalike check found nothingWhat an empty result means, why it always comes with a coverage count, how to widen the check, and when a known impostor does not show up.Updated
Still stuck?
Ask the people who run the scanner.
Send the domain and what you expected to see. We look at the same scan you are looking at and write back with what it means and what to change.
