Skip to content

Opt a host out of scanning

To stop ssltest.com from checking a host, publish a single DNS TXT record. No form, account, or waiting is involved: the record is checked on every request, so the opt-out applies as soon as it is visible and stops the moment it is removed.

Add this DNS record
optout.YOURDOMAIN.  IN  TXT  "ssltest.com"

Replace YOURDOMAIN with your domain. To opt out example.com, create a TXT record at optout.example.com with the value ssltest.com.

A record on the registrable domain covers every host under it. A single hostname can also be opted out on its own — publish the record at optout.mail.example.com to cover mail.example.com alone — which matters when a subdomain is run by a different team. Both names are checked on every request.

Once the record resolves, ssltest.com returns a refusal instead of a report and never opens a connection to the host. Publishing the record proves control of the zone's DNS, so no other verification is needed.

Where the connections come from

Checks, mail probes included, connect from five scanning servers. All of them are named in DNS, so the source is verifiable rather than a claim:

scan.ssltest.com
136.144.237.216
37.97.229.127
93.119.6.204
136.144.248.241
37.97.229.137
2a01:7c8:d008:401:5054:ff:fe7e:6e98
2a01:7c8:fffd:bb:5054:ff:fed5:9c8b
2a01:7c8:bb0d:2ea:5054:ff:fec1:c3d7
2a01:7c8:d007:152:5054:ff:feef:bd4e
2a01:7c8:fffd:c9:5054:ff:fe1e:51c

Every one of these addresses carries a PTR record pointing to scan.ssltest.com, and scan.ssltest.com resolves back to the same addresses. A reverse lookup followed by a forward lookup confirms the source, and a third party borrowing the name in a greeting fails the same check. SMTP, POP3 and IMAP probes greet with EHLO scan.ssltest.com for the same reason.

Checks on other protocols reach IPv4 addresses from a larger set of scanning hosts, which carry their own provider hostnames. Filtering by source address therefore suits mail, and the DNS opt-out above covers every protocol at once. The full list of addresses and the robots.txt token are on the bot page.

What the scanning traffic is

A requested check produces two kinds of request: DNS-over-HTTPS lookups, which go through public resolvers and never reach the scanned host directly, and TLS or STARTTLS connections to each resolved address to read the certificate chain and the negotiated parameters. Mail protocols connect straight from the two scanning servers above, over IPv4 and IPv6 alike.

No application data is sent beyond what a normal client handshake requires. For STARTTLS protocols the probe upgrades the connection and disconnects without issuing further commands. Reading the supported protocol versions and cipher suites takes a separate handshake per combination, so a single check appears in a server log as several hundred connections from one address inside about a minute, and then nothing further. A repeat appears only when someone requests another check.

Frequently asked questions

How long does the opt-out last?

Exactly as long as the TXT record exists. It is checked live on every request. Remove the record and scanning resumes on the next one.

Do I need an account or to submit a form?

No. The DNS record is the whole mechanism. Controlling the zone's DNS is the authorisation.

Connections arrived on port 25 and no mail followed.

A check on a mail protocol opens the session, reads the STARTTLS response and the certificate, then disconnects before any message envelope. No delivery is attempted and no recipient is named. The greeting EHLO scan.ssltest.com identifies the source, and the DNS record above stops the connections.

Does this also stop the TLS connection?

Yes. When the record is present the host is not scanned at all, so no connection is made to it.

Is any data sent to my server beyond the handshake?

No. The probe completes the standard TLS or STARTTLS negotiation needed to read the certificate chain and connection parameters, then disconnects.

Something still looks wrong, or I cannot publish DNS.

Email fili@ssltest.com with the relevant timestamps and log excerpts and we will help, including blocking a host out of band where a DNS record is not possible.