Abuse contact
Secure Your Server lets visitors run security checks against domains they submit. We try hard to make abuse difficult (see our terms of use):
- Full, active port scans (nmap) are only unlocked after proof-of-control of the target domain.
- All other checks are passive (standard protocol negotiation: TLS handshake, SSH banner, DNS lookups), comparable to what any browser or mail client does routinely.
- Requests are rate-limited per IP address.
- Scanned targets and requesting IPs are logged for up to 30 days for abuse investigation.
- The mail delivery test generates only random, single-use, short-lived (15 minutes) addresses and is rate-limited per IP address too, so the receiving mailbox can't be flooded or used as an open relay/backscatter target.
Think your system was scanned without authorization?
Contact us at security@chrislo.de with the affected domain and, if possible, the approximate timestamp. We will investigate using our logs and can block further scans against your infrastructure on request.
The same contact applies to any other suspected misuse of this service, including the mail delivery test (e.g. abusive content sent to our test mailbox).
See the imprint for the operator's full contact details.