Once your company domain is verified, colleagues who sign up with an address on it can land straight in your organization.
Turn on joining by email domain from your organization settings, or while setting up the organization. It is off by default.
Colleagues who sign up with an address on your verified domain join your organization as Members, no invitation needed.
They join only after proving they own the address: a code sent by email, or signing in with Google or GitHub.
When joining is off, sign-ups on your domain are refused with a message to ask your admins for an invitation, instead of creating a second organization.
Available on the Team and Enterprise plans.
Each company domain belongs to one organization. Verifying it settles any other organization's unverified claim.
The dashboard reminds admins when the organization's domain is not verified yet.
Version 1.20.1
Certificates on domain reports
Fix
Domain reports no longer claim a domain has no SSL certificate when it does.
Reports older than a day showed "No SSL certificate found" because their certificates had expired from our records. They are now kept for 90 days.
A report whose certificates are missing fetches them again the next time it is opened, no rescan needed.
A domain with no certificate in Certificate Transparency logs now says so, with the date it was checked.
When certificates cannot be loaded for a moment, the report says so and offers a reload instead of reporting none.
Integrations directory
Integrations
Every way to use mlab.sh outside the website, on one page.
MCP for AI assistants and Claude Code plugins, VS Code and JetBrains extensions, a GitHub Action, an n8n node, a Chrome and Firefox extension and the mlab CLI.
Read-only audits of cloud accounts, Proxmox VE, UniFi and MikroTik, plus our open-source security scanners.
Each entry links straight to its store listing and to its source code.
Easier reference pages
Website
The long pages of the site now share the layout of a domain report.
A navigation rail that follows you down the page and highlights where you are.
Tools grouped by category, with search.
Glossary sorted from A to Z, with a direct link to every term.
Cheat sheets split into sections, such as HTTP status codes by class or ports by service.
Terms of service, privacy policy and terms of sale with a link to every article.
The changelog now lists releases by version.
Version 1.20.0
Faster pages
Performance
Result pages answer faster, even under load.
Domain, IP and hash pages load faster, and stay fast when many people use mlab at once.
File lookups by MD5 or SHA-1 answer faster.
Pasted lists of indicators are triaged several at a time.
Version 1.19.0
Team roles
Organization
Decide who in your organization can do what.
Four roles: Owner, Admin, Member and Viewer.
Viewers can read everything but cannot run scans or change anything.
Admins manage members, API keys, webhooks and integrations; only the owner manages billing.
Change a member's role, remove a member, or transfer ownership from the team page.
Active sessions
Security
See every browser signed in to your account and sign out the ones you do not recognise.
Stay signed in on several devices at once.
Each session shows its browser, IP address and last activity.
Sign out a single session, or every session except the one you are using.
Changing your password now signs out all your other sessions.
Organization audit log
Organization
A record of who changed what in your organization.
Member invitations, API keys, MCP tokens, 2FA changes, webhooks, infrastructure and billing events in one timeline.
Filter by category and period, and export to CSV.
History of 7 days on Free, 30 days on Pro, 60 days on Team and Enterprise.
Version 1.18.4
New dashboard and unified scan history
Workspace
One place for everything you and your team looked up.
Switch the dashboard between your own activity and your organization's.
A single scan history across every lookup type, with filters.
Team subscriptions show which member manages billing.
PDF reports
Reports
Download domain and RedKit results as ready-to-share PDF reports.
Same findings and score as the result page, laid out for reading and printing.
Consistent output whatever your browser or theme.
Version 1.18.0
Team activity
Organization
See what your organization investigated, and who looked.
A feed of every lookup across the team, with the member on each line.
The indicators your team reached for most, and how many people looked at each.
Tells a paid scan apart from a result page that was only viewed.
Outbound webhooks
Integrations
Push mlab events to your own tools.
Native formats for Slack, Discord and Microsoft Teams, plus a signed generic JSON format.
Choose which events each endpoint receives.
Automatic retries, a delivery log and one-click replay of failed deliveries.
Cases
Investigations
Group the indicators of an investigation and discuss them with your team.
Add indicators to a case from any lookup page, or paste a list.
Comment on the case or on a single indicator.
Open and close cases as the investigation moves.
Domain watch and change detection
Monitoring
Know when a domain or an IP changes.
Domain and IP pages show what changed since the previous lookup.
Schedule recurring scans of any domain, including look-alikes of your brand and your suppliers.
Get an email or a webhook when a scheduled scan finds changes.
Lookup exports
Integrations
Take any lookup result into your tickets, spreadsheets and threat platforms.
Export as JSON, CSV, STIX 2.1 or MISP from every lookup page.
Indicators are defanged where it matters, so they are safe to paste.
Version 1.16.5
Crypto addresses and email security
Lookups
Two lookups rebuilt to answer on the first try.
Crypto address lookup with detection of the chain and the address format.
Live email posture for any domain: MX, SPF, DMARC and DKIM.