1.5.52
Released 22 September 2026
Improved
-
A retried issuance no longer shows the previous attempt's error. Once a later attempt gets past the DNS-record step and hands the order to the propagation check, the earlier attempt's red error is cleared instead of sitting next to "issuance pending" until the certificate is issued.
-
Discovery no longer records the server's fallback answer to names it made up. A name the deep-SNI crawler only tried because it appeared in a certificate on the address (the apex of a wildcard, a SAN), that DNS does not point at that address, and that the server answered with a certificate not covering it, is dropped instead of listed —
example.comon the IP ofapp.example.com, answered with*.hosting-provider.net. A name DNS does point at the address, answered that way, is kept and tagged Name mismatch in every endpoint list (name_mismatchin the API, counted per address).
Changed behaviour
Rows earlier scans recorded for made-up names are deleted on the next scan, with no endpoint gone alert, so a source's name and certificate counts, its Scan History success count and the Certificates tab shrink. A certificate that was only ever seen through such names — typically a server's default certificate on a hostname source — leaves the inventory with the next cleanup and any open finding on it resolves automatically; nothing on the server changed. A resolver outage during a scan never removes anything: names DNS did not answer for are kept and flagged.