Last updated: 21 June 2026 · This page is canonical; if anything you see in the wild contradicts what's here, this page wins.
1. What DomainScores is
DomainScores.net is a public security-grading service for domain names. We scan the public DNS namespace continuously and produce a single letter grade (A+ through F, with additional explicit states X (registered but DNS unreachable), Z (NXDOMAIN — the name no longer resolves), and U (still being classified)) for each domain. Each scan applies a published set of binary checks across DNS, email authentication, TLS, web security headers, and registration hygiene.
DomainScores is operated by James McGee under Pragmatic Security (Ireland). The methodology is published in full at /methodology. If you operate a domain and want to know what we observed, the public check at the homepage will show you exactly what was measured — there is no paywall on your own grade.
2. What we scan
Every domain in our active corpus is touched in two phases:
- Classification (DNS-only). Public DNS queries to the authoritative nameservers for the domain — A, AAAA, MX, NS, TXT, SOA, CAA, DS, DNSKEY, plus PTR for any returned MX IPs. We do not issue zone transfers or any non-public DNS request. We rate-limit our authoritative queries and respect throttling responses.
- Scoring (HTTPS). One HTTPS handshake on port 443 — we read TLS handshake metadata, the certificate chain, and the response headers from a single HEAD request to / (occasionally a ranged GET if a server mishandles a HEAD). That's it.
3. What we do not do
- No authentication attempts — we never log in, submit forms, or test credentials.
- No vulnerability probes — we do not test for known CVEs, attempt SQL injection, send malformed packets, or any other exploit traffic.
- No page crawling — we read only the response to a single GET on /. We do not follow links, fetch assets, or index content.
- No email — we never send mail from our scanner IPs. If you receive an email purporting to be from DomainScores, treat it as suspicious and contact us.
- No paid-data API hits against your services — every request goes to a public, unauthenticated endpoint.
- No traffic outside DNS port 53 and HTTPS port 443 / 80 (for the HSTS redirect check).
4. How to identify our traffic
HTTP/HTTPS requests from DomainScores carry the following User-Agent string: Mozilla/5.0 (compatible; DomainScores/2.1; +https://www.domainscores.net/headers)
All scan traffic originates from the following OVH-hosted IPv4 addresses (our scanning nodes). This list is authoritative — if traffic claiming to be DomainScores comes from any other source, it is not us. A machine-readable copy is published at /scanner-ips.txt.
Every node has forward-confirmed reverse DNS — the IP resolves to the hostname shown and that hostname resolves back to the IP. We publish any additional source IPs here at least 7 days before they begin scanning.
- 54.38.248.204 — node-01.domainscores.net
- 54.38.176.226 — node-02.domainscores.net
- 51.77.217.119 — node-03.domainscores.net
- 37.187.154.156 — node-04.domainscores.net
- 51.255.91.138 — node-05.domainscores.net
- 54.36.179.182 — node-06.domainscores.net
- 51.83.4.94 — node-07.domainscores.net
- 37.187.137.193 — scanner-01.pragmaticsecurity.ie
5. Scan cadence
- Each domain is re-scanned at least every 90 days. Most domains are re-scanned more frequently — between weekly and monthly depending on TLD and prior grade.
- Owner-triggered re-scans complete within 24 hours of request via the dispute form.
- Per-host rate limit: at most one scan per domain per hour, regardless of source. We will not flood you.
6. Data we collect and keep
We do not retain raw HTTP response bodies, full zone-walk data, or any content beyond what is necessary to compute the 34 checks defined in the methodology.
- The result of each check (pass / fail / not-applicable), plus the minimal data needed to compute it: returned DNS records, TLS handshake parameters, certificate chain, and response headers from the single HTTPS request.
- Per-check timing, retry count, and the resolver / source IP used (for our own infrastructure analysis — never published per-domain).
- A grade history per domain, so owners and the public can see improvement over time.
7. Aggregate reporting and naming policy
DomainScores publishes aggregate statistics — by country, industry, TLD type, registrar age, and similar. We do not, and will not, publish or sell grades for individual named domains. A domain owner can look up their own grade at any time. We do not respond to journalist or researcher requests for a "name the worst" list.
8. Opting out
If you do not want your domain to be scanned, email [email protected] from an address provably tied to the domain (apex or technical contact per RDAP). Your message should include:
We commit to removing verified domains from active scanning within 7 calendar days, and to deleting historical scan data for those domains within 30 calendar days. We will reply confirming the action taken.
Opt-out is honoured for as long as the domain registration is held by the requesting party. If the domain changes hands, we may resume scanning the new registrant unless they themselves opt out.
- The domain(s) you want excluded.
- Confirmation that the requesting address is authorised (we will verify against the domain's public registration record).
9. Reporting abuse or unexpected behaviour
If you believe traffic from one of our published IPs is misbehaving — for example, requesting at higher than the stated cadence, hitting endpoints we say we don't touch, or attempting any form of authentication — please tell us immediately:
- Email [email protected] with the timestamp(s) (in UTC), the affected resource, and a sample of the offending log line if possible.
- We will acknowledge within 24 hours and either explain or stop the offending behaviour within 72 hours. Substantive incidents are published in our transparency log.
10. For researchers
If you are an academic or independent security researcher and want bulk access to the dataset for measurement work, write to [email protected]. We provide aggregate-only data dumps free of charge for non-commercial research, subject to a brief data-use agreement reflecting the no-individual-naming policy.
11. Methodology critique
We treat methodology disagreement as a feature, not a fault. If you believe a check is wrong, mis-weighted, or generates false positives or negatives, write to [email protected] with the specific check ID, the domain (or anonymised pattern), and what you observed. Substantive issues are published in the methodology changelog and addressed in writing.
12. Changes to this page
Material changes (new IPs, new scan behaviour, new data retention practices) are dated at the top of this page and announced 7 days before they take effect. Minor edits (typos, link fixes) are made inline without notice.
Contacts (canonical)
- Opt-out / abuse: [email protected]
- Methodology questions: [email protected]
- Press / general: [email protected]