Marchpost
Menu

About our scanner

Last updated Sep 7, 2026

What our scanner does

Our scanner identifies itself as Marchpost-Scanner/1.0 (+https://marchpost.com/scanner) and every request comes from our published infrastructure. If you have seen it in your logs, this page explains exactly what it did.

Checks we perform on any domain

  • DNS lookups over DNS-over-HTTPS: MX, TXT, NS, CAA, DS, CNAME and A records. This is public data and generates no traffic to your servers.
  • One TLS handshake to port 443 to read the certificate, plus two additional handshakes that request TLS 1.0 and TLS 1.1 specifically, to determine whether obsolete protocols are still accepted.
  • One HTTP request to http:// to see whether it redirects, and one to https:// for your homepage, following up to six redirects.
  • One request each to /.well-known/security.txt, and to a small fixed list of common subdomains, to check for DNS records pointing at decommissioned third-party services.

Things we never do

  • We do not port-scan. We connect to port 443 and nothing else.
  • We do not attempt to log in, guess credentials, or submit forms.
  • We do not attempt to exploit anything, inject anything, or fuzz any input.
  • We do not crawl your site. We fetch your homepage and a short fixed list of standardised paths.
  • We do not run scans faster than a handful of requests per domain, and we honour a total budget of a few seconds per domain.

Deeper checks require proof of ownership

Checks that look for exposed configuration files — .env, .git/config, database dumps, debug logs — only ever run against a domain after its owner has proven control by publishing a DNS TXT record we generate. We will not run those probes against a domain on somebody else’s say-so.

Opting out

Please use our contact form from an address at the domain, or add Marchpost-Scanner to your robots.txt disallow rules, and we will stop. Denylist requests are permanent and apply to every customer.