Pin Host to IP

Pin a hostname to a specific IP for Guard's scanner when public DNS does not match how the host should be reached.

Pin Host to IP (the card on Settings → Scanning) lets you tell Guard's web scanner to connect a hostname to a chosen IP instead of trusting public DNS.

Use it for split-horizon DNS, hosts with no public record, or hosts whose public DNS returns a private or wrong address from Guard's vantage point.

How the pin is applied

Only the TCP connection target changes. Above the socket:

  • The hostname in the URL stays the same
  • The HTTP Host header stays the hostname (virtual-host routing still works)
  • TLS SNI stays the hostname (certificates still match)

The asset in Guard remains the hostname, not the pinned IP. A pin does not rewrite DNS anywhere else.

Add pins

  1. On Settings → Scanning, click Edit on the Pin Host to IP card.
  2. Enter a Hostname and an IP address, then add the row. To add many at once, import a text file with one hostname:ip pair per line (up to 1 MB).
  3. Click Verify IPs. Each row shows a status.
  4. Click Save. Saving shows Host overrides updated.

The card then shows how many hostnames are pinned, for example 3 hostnames pinned to custom IPs.

Ownership check

Verify IPs checks whether each IP belongs to you:

Status

Meaning

Verified

The IP is in one of your connected cloud accounts.

Provider not configured

The IP belongs to a cloud provider you have not connected. Configure that integration so Guard can verify it.

Not in account

The IP was not found in your connected account for that provider.

Unknown

The IP could not be matched to any known cloud provider.

If any row is not Verified, Guard lists it under The following overrides could not be fully verified. You can still save by checking I understand these overrides are unverified and may cause scans to target incorrect hosts. Without that check, saving shows Verify IPs or acknowledge unverified pins before saving.

Limits and validation

  • Up to 256 pins. The editor shows the count, for example 12 / 256.
  • IPv4 addresses only. Private and reserved IPs are not allowed.
  • Hostnames are lowercased, and duplicate hostnames are rejected.
  • Reserved names such as localhost, and names ending in .localhost, .local, .internal, or .arpa, are blocked.

Who can edit

Any user who can manage settings. You do not need Praetorian to make changes.

Authenticated scanning, where the scanner signs in to a web application, is not configured here. You set that up on the web application seed.