Overview

Acceptable use

You must be authorized to scan the host#

If you rent the server, authorization usually also means checking your provider's policy on port scanning your own instance.

The design limits misuse#

  • There is no field to type a target. The connecting IP is the only target.
  • Shared address space is refused, so a scan cannot hit a neighbour behind the same CGNAT.
  • Proxy, VPN and Tor origins are refused on a best effort basis, so the connecting IP is more likely to be a host you actually control.

Reporting a problem#

Security disclosures, false positives and opt out requests go through qsa.sh/contact, which routes to the support queue. There is no inbound email server, so mail sent to a qsa.sh address is not received.

Next#