Acceptable Use Policy

Last updated: 2026-08-26 · Part of the Terms of Service.

SSLScan actively checks the endpoints you point it at and discovers names from public Certificate Transparency logs. Pointed at your own infrastructure that is ordinary security hygiene; pointed at someone else’s it can be intrusive or unlawful. This policy draws that line precisely, because a product that is vague about it does not deserve anyone’s trust.

1. The one rule that matters

Only monitor what is yours to monitor. You may point SSLScan only at domains and systems that you own, or that you administer, or that their owner has explicitly authorised you to assess - in writing, if you are a contractor or MSP.

Entering a hostname into the product is your representation that this is true. SSLScan reads a certificate the way a browser does - an unauthenticated TLS handshake - but it does so deliberately and on your instruction, so the authorisation to check a host is yours to hold. For public addresses, “I was curious” is not authorisation.

2. What normal use looks like

  • Monitoring your organisation’s domains and endpoints, including those run for you by a hosting provider.
  • Discovering subdomains of your own domains via public Certificate Transparency logs.
  • An MSP monitoring a client’s estate under a service agreement that covers it.
  • Converting certificate files in the toolkit - they stay in your browser anyway.

3. What is forbidden

  • Scanning networks or hosts you are not authorised to assess, however harmless a TLS handshake seems.
  • Using the service to select, prepare or support attacks on any system - reconnaissance for intrusion is intrusion’s first step, and we want no part of it.
  • Attempting to overwhelm, probe or bypass the security of the service itself, or of other tenants. (Good-faith security research under our disclosure policy is welcome and explicitly not a breach.)
  • Reselling or white-labelling the service without an agreement with us.
  • Automating account creation or evading plan limits with multiple accounts.
  • Any use that violates applicable law - computer-misuse, export-control or otherwise.

4. Guardrails built into the product

Policy is backed by engineering: checks are rate-limited and polite, subdomain discovery reads only public Certificate Transparency logs, and every certificate read is a single unauthenticated TLS handshake - nothing more. The product is read-only end to end: it has no capability to change, exploit or load-test anything.

5. Enforcement

Violations lead to warnings, feature suspension, or account termination, proportionate to the harm and to whether the violation was a mistake or a pattern. Where scanning targets third parties, we may suspend first and ask second - the third party’s protection comes ahead of the violator’s convenience. Unlawful activity is reported to authorities where the law requires it.

6. Reporting abuse

If you believe SSLScan has been used against infrastructure you are responsible for, e-mail abuse@sslscan.net with the source addresses and timestamps you observed. A human reads it, investigates, and answers.