Authorized deep scan

Scan the real server — not just the surface.

Our free scan reads what's public. The deep scan goes further: open ports, exposed services and version-level vulnerabilities on your actual origin server — the one behind your CDN. Because that's intrusive, we run it only after you prove you own the domain and authorize the test.

How it works

  1. 1Confirm your work email — so we can deliver the report to a verified inbox.
  2. 2Prove domain control — add one DNS TXT record we give you. This is what makes the scan legal and safe.
  3. 3We scan your verified origin from an isolated WoneShield scanner and email your full report.

Active scanning of a system you don't own or aren't authorized to test is illegal. Verification and your explicit authorization aren't red tape — they're what separate a security service from an attack. We enforce both.

Request your scan

Two-step verification (email + DNS) protects everyone — we never scan a target that hasn't been proven and authorized.