How scanning works

When you run a check against a domain, SATools makes read-only lookups against public data about that domain: DNS records over DNS-over-HTTPS, HTTP requests to well-known paths like /.well-known/security.txt, and queries to public registries โ€” Certificate Transparency logs (crt.sh) and RDAP for domain registration data. Requests identify themselves with the user agent SATools/1.0.

What we don't do

If your domain is being scanned

Every check here reads data your domain already publishes to the public internet โ€” the same information any DNS resolver, browser, or certificate authority can see. If you believe our traffic is causing a problem, or you want to discuss being excluded, see report abuse.