DNSAUDITBOT
What our crawler does on your site
DNSAuditBot is the crawler behind the HTTP and SSL checks on DNSAudit.io. If you found it in your logs, someone ran a scan of your domain on our site. This page explains exactly what it requests and how to reach us.
How to recognize it
Requests come with this user agent and from this address:
User agent: DNSAuditBot/1.0 (+https://dnsaudit.io/bot)
Source IP: 155.138.198.183
If the address changes, we'll update this page.
What it requests
It makes a GET request for the homepage of the scanned domain, once over HTTP on port 80 and once over HTTPS on port 443. If the response is a redirect, it follows it, up to five hops, and only to standard ports on publicly reachable addresses.
From each response it reads the status code, the response headers and, over HTTPS, the certificate your server presents. It stops reading as soon as the page content starts, so it does not download your pages.
What it does not do
It doesn't follow links or request any other page, which is also why it doesn't read robots.txt. It doesn't submit forms, try to log in, send attack payloads or scan ports. It only runs when someone scans your domain, and results are reused for up to an hour, so repeated scans usually don't send new requests.
Opting out
To have your domain excluded, email security@dnsaudit.io with the domain name. We may ask you to confirm that you manage it. Once excluded, scans of that domain and its subdomains skip these checks entirely.
You can also block the user agent or the IP address above at your firewall or CDN. Our scans will then report the site as unreachable for this check.
Questions
If the crawler causes a problem on your site, or does something this page doesn't describe, write to security@dnsaudit.io.
