/internetscan.org

You're probably here because traffic from one of our scanner IPs turned up in your logs.

internetscan.org is a small, non-commercial security research project. We measure publicly routed networks in configured country and territory populations to see what services are reachable. The current registry is published in the console and can expand without changing the measurement model. Most census work is IPv4; any IPv6 pilot is labelled separately. This is in a similar spirit to ZMap, Censys, and Shadowserver, just at much smaller scale.

Our probes do not attempt credentials, bypass access controls, run exploits, or modify systems. We record bounded facts returned by normal, unauthenticated connections: service and protocol handshakes, TLS and HTTP metadata, screenshots, and—where an endpoint makes content or a listing public without authentication—bounded evidence needed to understand that exposure. Collection limits and country cadence are configured explicitly; adding a country does not automatically enable jurisdiction-specific probe types.

Scanner traffic comes from hosts with reverse DNS under *.internetscan.org (e.g. scan.internetscan.org; more may be added as scope grows).

Opting out

Send a note to abuse@internetscan.org with the IPs, CIDRs, or ASNs you'd like excluded and we'll add them within 24 hours.

The current exclusion list lives at /exclusions.txt.