Pin Host to IP
Pin a hostname to a specific IP for Guard's scanner when public DNS does not match how the host should be reached.
Pin Host to IP (the card on Settings → Scanning) lets you tell Guard's web scanner to connect a hostname to a chosen IP instead of trusting public DNS.
Use it for split-horizon DNS, hosts with no public record, or hosts whose public DNS returns a private or wrong address from Guard's vantage point.
How the pin is applied
Only the TCP connection target changes. Above the socket:
- The hostname in the URL stays the same
- The HTTP
Hostheader stays the hostname (virtual-host routing still works) - TLS SNI stays the hostname (certificates still match)
The asset in Guard remains the hostname, not the pinned IP. A pin does not rewrite DNS anywhere else.
Add pins
- On Settings → Scanning, click Edit on the Pin Host to IP card.
- Enter a Hostname and an IP address, then add the row. To add many at once, import a text file with one
hostname:ippair per line (up to 1 MB). - Click Verify IPs. Each row shows a status.
- Click Save. Saving shows Host overrides updated.
The card then shows how many hostnames are pinned, for example 3 hostnames pinned to custom IPs.
Ownership check
Verify IPs checks whether each IP belongs to you:
If any row is not Verified, Guard lists it under The following overrides could not be fully verified. You can still save by checking I understand these overrides are unverified and may cause scans to target incorrect hosts. Without that check, saving shows Verify IPs or acknowledge unverified pins before saving.
Limits and validation
- Up to 256 pins. The editor shows the count, for example 12 / 256.
- IPv4 addresses only. Private and reserved IPs are not allowed.
- Hostnames are lowercased, and duplicate hostnames are rejected.
- Reserved names such as
localhost, and names ending in.localhost,.local,.internal, or.arpa, are blocked.
Who can edit
Any user who can manage settings. You do not need Praetorian to make changes.
Authenticated scanning, where the scanner signs in to a web application, is not configured here. You set that up on the web application seed.