Skip to content

The Qlyne scanner

QlyneScanner/1.0 in your logs is the Qlyne scanner. It checks a site from the outside, seeing only what any visitor sees, and writes a report for the owner of the site.

Only the owner of a Qlyne account, for a domain they proved is theirs with a TXT record at _qlyne.<domain>. The scanner never picks a domain on its own and doesn’t follow links to other domains.

A scan makes at most 30 requests to the site, and the next one can start only 10 minutes later:

  • the home page, over HTTPS and over plain HTTP, to check the redirect to HTTPS;
  • one TLS connection to read the certificate, and one attempt each with TLS 1.0 and TLS 1.1, which a well-configured server refuses;
  • /.env, /.env.local, /.env.production and /.git/HEAD;
  • up to 5 scripts of the home page, from the same domain, and the source map of each.

It also reads public DNS records, through a public resolver, and the public certificate logs (crt.sh). Every request is a GET, without cookies.

It doesn’t log in, submit forms, try passwords, send attack payloads or query databases. It doesn’t keep what it reads: the report shows the names of the variables in a public .env, never their values, and secret keys appear masked.

The requests carry the Qlyne-Scanner header, signed with the connector secret of the site, so the scanner trap of the site doesn’t block the scan. Every other rule applies to it as to any visitor.

If the scanner runs on a domain you own and you didn’t ask for it, write to [contact e-mail] with the domain. If you are the account owner, removing the TXT record stops new scans.