Detection Alone Is Not Ownership
A crawl that lists Gotham Bold on checkout.example.com answers one question: what is live? It does not answer the question an auditor, a client, or a foundry will ask next: do you have a license that covers this family on this domain?
That is what license management is for. You register the grants you actually hold. On every later scan, FontScanner tries to match each commercial detection to those records.
If there is a match — same family, and a domain the license covers — the report says Verified. If you own the family but not this host, it says Domain not covered. If nothing in the inventory fits, it says Missing.
The matching layer is optional. FontScanner still finds fonts if you never register a license. Matching is there when you want the scan and the paperwork in the same place. Start at Font License Compliance or, when you are signed in, My Font Licenses.
What You Register (Once)
A useful license record is not a font filename. It is the family plus the commercial facts:
- Font family (Gotham, not only
Gotham-Bold.woff2) - Vendor (Monotype, Adobe, Hoefler, a reseller, an agency)
- License type (web, desktop, app, server, enterprise, open source)
- Covered domains — or leave domains empty for an org-wide desktop/app style grant
- Seats, purchase date, renewal date
- Proof of purchase (invoice or EULA PDF)
You can keep the inventory even between scans. It is a register, not a one-off checklist. Why a sheet is a poor substitute: Company Font License Inventory.
What Happens on the Next Scan
- FontScanner crawls the site (or extracts a PDF) and classifies families against the commercial catalog.
- For each typically-paid detection, it looks up your licenses at family level.
Gotham Boldandgotham-bookboth hit a record named Gotham. - It then checks host coverage. A license for
example.comcoverswww.example.comandapp.example.com. It does not coverotherbrand.com. - The report writes a status on that row. Public and shared links do not leak vendor names or PDFs — those stay with the account that owns the scan.
You do not re-upload the invoice on every crawl. Register once; matching runs again whenever you scan.
How to Read the Match
| Status | Meaning | Typical next step |
|---|---|---|
| Verified | Family matches and this host is covered (or the license has no domain restriction) | Keep using it; watch seats and renewal |
| Domain not covered | You licensed the family, but not this website | Amend the web grant, buy the extra domain, or stop serving the files |
| Missing | No inventory row for this family | Find the invoice, register it, or replace the typeface |
| Unknown | Viewer is not the owner (share link) | Owner logs in; public reports stay private on purpose |
A longer walkthrough of each badge: Verified vs Missing. Matching is a triage layer, not a courtroom. The EULA still wins: Font Licensing 101.
A Worked Example
You add a web license: family Gotham, vendor Monotype, domains acme.com, PDF attached.
Then you scan shop.acme.com:
| Detected | Match |
|---|---|
| Gotham Bold | Verified — family + parent domain |
| Helvetica Neue | Missing — nothing registered |
| Inter | Catalog: open source — still confirm OFL if you self-host |
Helvetica Neue is the launch blocker. Register a real web grant for it, or swap it, before you treat the report as clean. How to prove ownership in an audit: Prove You Own Your Website Fonts.
Why Matching Belongs Next to the Crawl
Foundries do not ask whether your designer “meant to” use the font. They ask whether this domain is serving this family without a grant. Desktop seats do not answer that — see Desktop vs Web Font License.
If you cannot show the invoice and the domain list beside the live file, you are arguing from memory. Inventory plus automatic matching is how you stop arguing.
