About our scanner
Last updated Sep 7, 2026
What our scanner does
Our scanner identifies itself as Marchpost-Scanner/1.0 (+https://marchpost.com/scanner) and every request comes from our published infrastructure. If you have seen it in your logs, this page explains exactly what it did.
Checks we perform on any domain
- DNS lookups over DNS-over-HTTPS: MX, TXT, NS, CAA, DS, CNAME and A records. This is public data and generates no traffic to your servers.
- One TLS handshake to port 443 to read the certificate, plus two additional handshakes that request TLS 1.0 and TLS 1.1 specifically, to determine whether obsolete protocols are still accepted.
- One HTTP request to
http://to see whether it redirects, and one tohttps://for your homepage, following up to six redirects. - One request each to
/.well-known/security.txt, and to a small fixed list of common subdomains, to check for DNS records pointing at decommissioned third-party services.
Things we never do
- We do not port-scan. We connect to port 443 and nothing else.
- We do not attempt to log in, guess credentials, or submit forms.
- We do not attempt to exploit anything, inject anything, or fuzz any input.
- We do not crawl your site. We fetch your homepage and a short fixed list of standardised paths.
- We do not run scans faster than a handful of requests per domain, and we honour a total budget of a few seconds per domain.
Deeper checks require proof of ownership
Checks that look for exposed configuration files — .env, .git/config, database dumps, debug logs — only ever run against a domain after its owner has proven control by publishing a DNS TXT record we generate. We will not run those probes against a domain on somebody else’s say-so.
Opting out
Please use our contact form from an address at the domain, or add Marchpost-Scanner to your robots.txt disallow rules, and we will stop. Denylist requests are permanent and apply to every customer.