What we did, and how to make us stop
If we contacted you about your website's configuration, you did not ask us to look, and it is reasonable to want to know exactly what we did. This page is the full answer. It is also the page to use if you want a finding corrected or your domain left alone — no account, no form, one email.
The short version
We loaded your home page once, the way a browser would, and read public DNS and public certificate records. We did not log in, guess at hidden paths, scan ports, or send anything crafted. We never publish an individual company's result. Email paul@mysecscan.com and we will correct a wrong finding or stop scanning your domain entirely.
Exactly what we requested
- One HTTPS GET of your home page, following redirects. We read the response headers, the cookies you set, and the HTML — the same bytes your site hands every visitor.
- One TLS handshake to read the certificate and which protocol versions the server offers.
- Public DNS lookups — MX, and the TXT records holding SPF, DMARC and DKIM. These are published records; anyone sending you email reads them.
- Public Certificate Transparency logs, to list hostnames certificates have been issued for. CT is a public, append-only log that every certificate authority is required to write to; we query the log, not your servers.
What we deliberately did not do
- No requests for paths you never published. We have a check that looks for files left in a web root — .git directories, .env files, database backups, admin panels. It is switched off unless the person running it has proved they control the domain, or we are working under a written engagement.
There is one further case, and we would rather state it than have you discover it: this check also runs in our own research batches, where findings exist only as a percentage across hundreds of companies. Those findings are never used to contact anyone and are never attributed to a company, including in a message to that company. So if we wrote to you about something specific, it was not this check — and if your domain was in a research batch, the only thing that left it was an anonymous +1 in a statistic. You can ask us either way. - No authentication. We did not log in, create an account, or use credentials of any kind.
- No port scanning and no service enumeration across your address space.
- No payloads. Nothing injected, fuzzed, or crafted to provoke an error. Every request was an ordinary one.
- No crawling. One page, not your site.
- We stop when told to. If your server or WAF returns a block, we record that and move on rather than working around it.
We never publish your result
Our published research reports aggregate percentages across hundreds of companies, with sample sizes. No individual company is named, and no per-company finding is published, ever. A list of individually weak sites would be a target list, not research. If we wrote to you about a specific finding, that finding went to you and to nobody else.
Why we think this is proportionate
Everything above is information your systems publish to anyone who asks: the response your web server gives every visitor, DNS records the email system depends on being readable, and a transparency log certificate authorities are obliged to write to. We do not go behind any access control, and we do not test whether one could be bypassed.
Where a person's data is involved — a name or address in a public business contact record — we process it on the basis of legitimate interests under Article 6(1)(f) GDPR, for the purpose of telling an organisation about a security weakness in its own infrastructure and offering to help fix it. We hold the minimum needed for that, we do not enrich it, we do not sell or share it, and the objection right below overrides the interest on request, with no reason required.
This is a description of what we do and why, not legal advice, and it is not a claim that any particular assessment is lawful in your jurisdiction. If you believe it is not, tell us and we will stop.
Corrections, objections and exclusion
One email to paul@mysecscan.com with your domain. You do not need an account, and you do not have to explain why.
- A finding is wrong. Tell us which one. We re-check, and if we got it wrong we say so plainly and correct it — including in any aggregate figure already published, with the correction noted rather than quietly edited.
- Stop scanning this domain. We add it to a do-not-scan list and it is excluded from every future run, including research batches.
- Stop contacting me. Separate from the above, and honoured on its own.
- What do you hold about me? We will tell you, and delete it on request.
We answer within five business days. If something is urgent — a finding you believe is live and exploitable — say so in the subject line and we will treat it as such.
The technical detail of how each check works is in how we scan; how we handle data generally is in the privacy policy.