Who we are
Ironfang Ltd is a UK company, registered in England and Wales under number 12764014. We build and operate developer and security products from the UK, and Ironfang Security is one of them.
The scanner is ours. It is not a research project and it does not sweep the internet: every connection belongs to a check that a customer asked for.
Why you may see this traffic
Ironfang Security runs the External Security Check: automated, low-impact security checks of a domain from the public internet. A customer adds a domain in the Ironfang portal, proves they control it and starts a scan.
If the traffic reached a system of yours, the most likely reason is that someone who controls a domain pointing at it asked for that domain to be checked. That may be you, a colleague, an agency or a hosting provider acting for the domain's owner.
Only verified, authorised domains
Before anything is checked, the customer adds a TXT record under the domain, which only someone who controls its DNS can create, and confirms they are authorised to test it. The record is checked again before every scan; if it is missing, the scan is refused.
Only the verified domain is checked, at the addresses its own DNS points to. Hostnames found in public certificate logs are listed for the customer and never scanned, and the scanner refuses to connect to private, loopback and other non-public addresses, whatever DNS says.
How to recognise it
Scanner traffic comes from the addresses below and every HTTP request carries the User-Agent shown.
Source addresses
87.242.201.101
This is the complete list. If it changes, this page changes first.
Reverse DNS
Dedicated scanner hostnames, with matching reverse DNS, are being set up. Until they are in place, the addresses above may not resolve to a name that says Ironfang Security, so rely on the address and the User-Agent.
User-Agent
Every HTTP and HTTPS request sends this, with a link back to this page:
IronfangSecurity/1.0 (External Security Check; +https://ironfang.com/security/scanning)What the traffic looks like
Everything a scan does:
- DNS lookups of the domain's records (addresses, nameservers, MX, TXT, CAA, DNSSEC, SPF, DMARC and DKIM at common selectors). They go through public resolvers, so your nameservers see the resolver rather than us.
- A handful of ordinary HTTP and HTTPS GET requests per host, such as the home page over HTTP and HTTPS and /.well-known/security.txt. No forms are submitted and nothing is logged in to.
- TLS handshakes to HTTPS ports to read the certificate and see which protocol versions and cipher suites the server accepts.
- One TCP connection attempt to each port on a short, fixed list. The connection is opened and closed; nothing is sent, and a greeting is read only from services that speak first, such as SSH.
- A search of public certificate transparency logs for related names. That touches the logs, not your systems.
The ports it tries
21FTP22SSH23Telnet80HTTP443HTTPS445SMB1433Microsoft SQL Server1521Oracle Database2375Docker API3306MySQL / MariaDB3389Remote Desktop (RDP)5432PostgreSQL5900VNC5984CouchDB6379Redis8080HTTP (alternate)8443HTTPS (alternate)9042Cassandra9200Elasticsearch11211Memcached27017MongoDB
It never attempts exploitation, password guessing or any login, fuzzing, SQL injection or cross-site scripting payloads, denial of service, or anything that writes to your systems.
Rate limits
Every scan job keeps to fixed limits, and the free service limits how often a domain can be scanned at all.
- At most 8 HTTP requests to any one host in a scan.
- At most 2 connections open to any one address at a time, with at least 150 milliseconds between connection attempts.
- A 8-second timeout on every connection and request, and a hard stop for each job after 2 minutes.
- A full scan of a domain at most once every 60 minutes, at most 20 scans a day per customer, and one scan running at a time per customer.
- A recheck repeats only the checks behind one finding, on one host.
Allowlisting the scanner
If your firewall, WAF or intrusion detection blocks the scanner, the customer's results will show checks that could not complete. To let it through, allow the source addresses above and, where your WAF matches on headers, the User-Agent.
Allow it for ports 80 and 443 at least, and for the other listed ports only if you want their exposure checked. We never switch to another address to get around a block; if the scanner is blocked, the check simply reports that it was.
Reporting a problem
If the scanner caused a problem, or you think a scan was not authorised, email security@ironfang.com or use the contact form. Please include:
- the source address you saw;
- the time, with its time zone;
- the destination address, host name or port that was reached.
From those three facts we can find the scan, the customer and the authorisation behind it, and stop a scan, or every scan by that customer, at once.
Opting a domain out
A domain is only checked while its verification record exists. If you control a domain and find a TXT record at _ironfang-verification under it that you did not create or no longer want, remove it: no further scan of the domain can start without it.
If you own a domain or network and want it excluded from Ironfang Security altogether, or you cannot reach its DNS, write to us at the address above with the domain or addresses, and we will stop checks of it.
Policies
Reporting a vulnerability in Ironfang itself is covered by our Vulnerability Disclosure Policy. Use of Ironfang Security is governed by the Terms of Service and the Acceptable Use Policy, and the documentation describes the scan policy a customer confirms.

