Security
Reporting a vulnerability in Inspect My DNS itself is very welcome, and we would much rather hear it from you than read it in a log. For anything else — a wrong result, a missing provider, a removal request — see Contact.
What helps
The URL or request, what you did, what happened, and what you expected instead. A proof of concept against your own domain or a domain you are authorised to test — please do not use somebody else’s to demonstrate a finding.
What we will do
Acknowledge as fast as a small team can, and aim for within three working days. We will tell you what we found, what we are fixing, and when it ships, and we are glad to credit you by whatever name you like once it does. There is no bounty programme — this is a self-funded project, and saying so is more honest than implying otherwise.
Disclosure
Please give us 90 days before publishing, or less if the fix is out sooner — we will not ask you to sit on something we have already fixed. If we go quiet on you, that is our failure and not a reason to keep waiting.
In scope
This site, its API, and the scanner itself — anything that lets a request make this service attack a third party, reach our internal network, read another user’s data or act as somebody else. SSRF in the enrichment fetches, key handling on /api/keys, and the domain input path are the parts we would look at first.
Out of scope
Findings about a domain we scanned are the report doing its job, not a vulnerability here — those belong with whoever runs that domain. Also out: missing headers with no exploitable consequence, rate limiting on unauthenticated reads, and reports produced by pointing a scanner at us. If you think one of those is exploitable anyway, send it with the exploit and we will read it properly.