Scanning Policy
Last updated: 3 August 2026
If you have arrived here from a log entry or a User-Agent string: we read publicly published DNS records and make a small number of standard HTTPS connections to measure security configuration. We do not probe, exploit, or attempt to access anything. To be excluded, email scanning@posturecheck.io.
What we do
PostureCheck operates two kinds of scan.
On-demand scans happen when a visitor enters a domain on the website. These run once, on request, and the results are returned to that visitor's browser and not stored.
Research scans are periodic surveys of publicly listed domains, used to produce aggregate statistics about email and web security adoption. Domains are sourced from the Tranco list, a research ranking of popular domains.
Both perform the same measurements:
- DNS queries for
TXT,MX,CAAandSOArecords — SPF, DKIM, DMARC and MTA-STS configuration - A TLS handshake on port 443 to read the certificate and determine which protocol versions are accepted
- A single HTTPS
GETto the root path to read response headers
That is the same information any web browser or mail server receives in the course of ordinary use.
What we do not do
- No port scanning — we connect only to 443
- No vulnerability probing, fuzzing or exploitation of any kind
- No authentication attempts, credential testing or attempts to access non-public resources
- No crawling — we request the root path only, and do not follow links
- No sustained traffic — a research scan contacts each domain once, then moves on
- No collection of page content, personal data or anything beyond configuration metadata
How to identify us
Our HTTP requests carry this User-Agent:
Mozilla/5.0 (compatible; PostureCheck/1.0; +https://posturecheck.io/scanning)
Both on-demand and research scans use the same identifier, so it is not possible to tell them apart from the User-Agent alone. Research scans run sequentially from a single host in a European datacentre; on-demand scans originate from our hosting provider's serverless infrastructure and arrive as a single isolated request.
Opting out
Email scanning@posturecheck.io with the domain or domains you want excluded. We will add them to an exclusion list that applies to research scans, and confirm once done. No justification is needed and we will not ask for one.
Two limits worth stating honestly. Exclusion applies to our own research scanning; it cannot prevent a visitor entering your domain into the public tool, since that is a single manual lookup of published records, in the same way anyone can run dig or open your site in a browser. And exclusion applies going forward — it does not remove your domain from aggregate figures already published, though those never identify individual domains in any case.
Publication
Research results are published only as aggregate statistics — by country and by sector. We do not publish per-domain results, do not name organisations, and do not operate a public index or leaderboard of scanned domains.
On-demand scans are never published in any form.
Reporting a problem
If our scanning has caused a problem, or you believe it is behaving in a way this page does not describe, email scanning@posturecheck.io. We will respond and, if needed, stop scanning the affected domains immediately while we investigate.
See also our privacy policy and methodology.