How scanning works
When you run a check against a domain, SATools makes read-only lookups against public data about that domain: DNS records over DNS-over-HTTPS, HTTP requests to well-known paths like /.well-known/security.txt, and queries to public registries โ Certificate Transparency logs (crt.sh) and RDAP for domain registration data. Requests identify themselves with the user agent SATools/1.0.
What we don't do
- No port scanning, no vulnerability exploitation, no login attempts.
- No connecting to internal or private network addresses โ every outbound request is checked and refused if it resolves to private, loopback or link-local space.
- No repeated automated scanning of a domain without a human initiating each run.
If your domain is being scanned
Every check here reads data your domain already publishes to the public internet โ the same information any DNS resolver, browser, or certificate authority can see. If you believe our traffic is causing a problem, or you want to discuss being excluded, see report abuse.