HostWithShery

Security and Abuse Policy

The scanners are restricted to public configuration and availability diagnostics and are designed to block internal/private destinations, open-proxy behavior and aggressive scanning.

Last updated: 2026-08-07
Check your own domainRun the main public-configuration diagnosis without leaving this page.

Free · No account · Public configuration only

Policy

The scanners are restricted to public configuration and availability diagnostics and are designed to block internal/private destinations, open-proxy behavior and aggressive scanning.

  • SSRF protection
  • private IP blocking
  • redirect revalidation
  • rate limits
  • restricted port checks

SSRF and destination validation

Hostnames are normalized and resolved before a server-side request. Private/reserved IPv4 and IPv6 ranges, localhost, internal-style hostnames and cloud metadata destinations are blocked. Redirect targets are resolved and revalidated on every hop rather than trusted from the first request.

Abuse controls

Full scans and focused tools are rate-limited; repeated scans of the same domain can be limited independently. Bulk inputs are bounded, redirect chains are capped and the port checker uses a small allowlist of common public service ports rather than arbitrary port ranges.

Scope boundary

The scanners inspect public availability and configuration only. They are not intended to exploit vulnerabilities, test credentials, enumerate internal services, reveal a CDN-protected origin, conduct aggressive port scanning or provide an open proxy.

Operational hardening

Production should use the distributed rate-limit store, platform WAF/bot controls, HTTPS, secure response headers, monitoring and regular backups. Old hosting accounts, DNS records, users, SSH keys and legacy subdomains must be removed or secured before the new domain is considered clean.