dnswatchdog.iodocs
Brand Protection

Runs and limits

The daily discovery run, the run statistics that report on it, and every bound that keeps search, fetching and AI spend flat.

The daily run

Discovery runs once a day for every organisation with a connected provider, at 04:00 UTC. A run is one pass of the whole pipeline for your organisation: it searches the brands whose search interval has passed, adds certificate-log candidates and the findings due a re-check, resolves and fetches them, assesses the new and changed pages, queues screenshots and sends notifications.

A run that would overrun its time budget stops assessing before it does and defers the rest; deferred findings keep their previous assessment (or take the fallback) and are picked up on the next run. Nothing is lost, only delayed.

Connecting a provider kicks off a run automatically: once the imported zones' brands have been inferred, a discovery run is queued for your organisation, so the first copycats surface within minutes rather than waiting for the next scheduled run. Adding a brand on its own does not start a run — the next scheduled run picks it up.

Run statistics

Run statistics, beside the View mode control on the Brand Protection page, lists recent runs, most recent first, one row per run:

ColumnMeaning
RunWhen the run started
Candidates by sourceHow many candidate domains each source produced — web search, certificate logs and scheduled re-checks
QueriesSearch queries spent
ProbedCandidates that entered the liveness funnel
ResolvedCandidates that resolved in DNS
ServingResolved candidates that served a page
EnrichedPages fetched into a snapshot
AssessedPages sent to the model
Below floorFindings hidden this run — below the risk floor, or not yet scored by the model
FindingsFindings written or updated by the run
SkippedCandidates skipped because the domain is ignored
ScreenshotsScreenshot captures queued
NotifiedNotifications sent
DurationHow long the run took

Read it left to right as a funnel: a healthy run shows queries producing candidates, most candidates resolving, a smaller share serving, and only new and changed pages being assessed. A run with Queries at zero searched no brands because none was due; a run with Assessed well below Enriched spent no model calls on unchanged pages.

Bounds

Every priced step is bounded. The defaults below are set per environment by DNS Watchdog.

BoundDefaultWhat it limits
Matching domains per brand search20Paging stops once this many matching domains have been seen for a brand
Result pages per brand search5Paging stops after this many pages regardless
Results per page20Results requested per search page
Search interval per brand7 daysA brand is not searched again until this has passed
Candidates probed per run2,000Domains resolved and fetched per organisation per run
Concurrent page fetches10Fetches in flight at once
Page fetch timeout10 secondsPer fetch
Page fetch size512 KBBytes read per fetch
Redirects followed5Hops per fetch
Page text sent to the model6,000 charactersPer assessment
Page text kept on the finding600 charactersThe excerpt shown on the finding page
Outbound links kept30Per page snapshot
Re-check interval7 daysKnown findings
Watched re-check interval1 dayFindings you are watching
Risk floor50Below this a finding is hidden
Re-assessment interval30 daysAn unchanged page is re-assessed after this
Model calls per organisation per day500Beyond this the fallback assessment stands in
Model calls across all organisations per day5,000Likewise
Screenshot captures per run500New captures queued per organisation
Screenshot refreshes per run100Existing screenshots re-captured per organisation

When a bound is reached the run degrades rather than fails: a search stops paging, a fetch is cut short, an assessment takes the fallback (and the finding stays hidden) and is retried the next day, a screenshot waits for the next run.

Operator controls

Two controls sit outside your organisation, operated by DNS Watchdog:

  • AI assessment runs whenever the environment's OpenRouter key is present; an operator can cut it off with a kill switch. Findings then carry the fallback assessment — and stay hidden — until it is restored.
  • Certificate-log monitoring is off by default and enabled per environment.

If findings stay hidden across the board — the run statistics show a high Below floor count and few visible findings — for more than a day, or the run statistics show runs with no queries for weeks, contact support.

On this page