This is an English translation provided for information. The authoritative text is the German version, Nutzungsregeln für die kostenlosen Scanner (German); in the event of any difference, that version applies. These rules are governed by German law, and the legal references below name German provisions.
§ 1 Who these rules apply to
(1) These rules apply to the use of the free checking tools on this website — the Web Security Check, the Email Security Check and the API Security Check. They apply whether or not you have an account.
(2) For registered users of the paid platform, the general terms and conditions (German) apply in addition and, for invited users, the terms of use for invited users (German). Where provisions overlap, those take precedence; this page is the short form for everyone else.
§ 2 What you may use the scanners for
(1) Only check domains you have authority over — that is, domains you operate yourself, domains your organisation operates, or domains you have been commissioned to check.
(2) If you are unsure whether you may check a domain: clarify it before you start the scan.
(3) In particular, it is prohibited to use the results in order to publicly disparage someone else's domain, to assert to third parties a security defect that the check does not substantiate, or to exploit a security vulnerability.
§ 3 What the scanners do — and what they do not
(1) The checks are passive. From the checked server itself, we retrieve only what it serves publicly of its own accord: HTTP response headers, the TLS certificate, public DNS records and the third-party resources embedded in the HTML it serves. In addition, we query public third-party directories — for example the browser vendors' HSTS preload list and, for continuous monitoring, public DNS blocklists. All that is transmitted in the process is the checked domain name or its IP address; which directories these are is set out in the privacy policy (German), section 13.1.
(2) There is no penetration test, no port scan, no login, no crawling of further pages and no exploitation of vulnerabilities. No access protection is circumvented and no protected area is entered.
(3) A result is the snapshot of an automated check from the outside. It replaces neither an audit nor a penetration test, and it is not evidence towards third parties.
§ 4 Who is responsible for what
(1) The provider supplies the tool. You decide which domain is checked — and in doing so you also decide whether the check is permissible.
(2) The provider may block use where there are concrete indications of misuse within the meaning of § 2.
(3) The free scanners are provided without any assurance of a particular availability. The provider's liability is governed by the statutory provisions; for intent and gross negligence, and for damage arising from injury to life, body or health, the provider is liable without limitation.
§ 5 Results and their visibility
(1) Result pages are reachable via an address that cannot be guessed and are not indexed by search engines (noindex in the document and as an HTTP header).
(2) There is no public ranking, no leaderboard and no searchable archive of other people's results. A result can no longer be retrieved once its retention period has passed; the details are set out in the privacy policy (German).
§ 6 Changes
The provider may change these rules. The version published at the time of use is the authoritative one; the date is given above.
§ 7 Information for the holder of a checked domain
§§ 1 to 6 are addressed to the person who starts a check. This section is addressed to the holder of a domain that has been checked. It contains the information that Art. 14 (1) and (2) GDPR requires for data that were not collected from you.
(1) Controller: The controller within the meaning of Art. 4 (7) GDPR is Wolf-Agents, owner Eduard Wolf, Vorderhainberg 21, 94496 Ortenburg, Germany, info@wolf-agents.com, telephone +49 151 46533415. No representative under Art. 27 GDPR has been appointed.
(2) Data protection officer: No data protection officer has been appointed; the conditions of § 38 BDSG (German Federal Data Protection Act) are not met. Please address data protection questions to the address in paragraph 1.
(3) Purposes and legal basis: The purpose is to provide the person carrying out the check with the requested result on the security configuration of the domain entered, and to update it during continuous monitoring. The legal basis is Art. 6 (1) (f) GDPR in conjunction with recital 49 GDPR.
(4) Legitimate interest: It lies in providing the checking tools in order to promote network and information security; for the access log and the prevention of misuse, additionally in operational security.
(5) Categories: What is processed is what the checked server or a public directory serves of its own accord — the domain name and the associated IP addresses, HTTP response headers, details from the TLS certificate, public DNS records and the third-party resources embedded in the HTML served. Where any of this can be attributed to a natural person — a name in a certificate, for instance — it constitutes personal data.
(6) Source of the data: The information does not come from you but from publicly accessible sources: the checked server when it is retrieved, the public DNS and the public directories named in paragraph 7. The retrieval is triggered by the person who starts the check; which domain is checked is not decided by the provider.
(7) Recipients: The recipients are the operators of the public directories queried — the browser vendors' HSTS preload list and, exclusively during the continuous monitoring of a domain stored in the dashboard, twelve public DNS blocklists and the certificate transparency service crt.sh. Which ones these are in detail, which item of information each of them receives and where they are based is set out in the privacy policy (German), section 13.1. That section also states what a transfer to a third country is based on.
(8) Storage period: The order record of a check is removed after 24 hours, the cached result of the Web Security Check after 7 days. For every checked domain there is a counter entry with the first and the last time of checking, which is removed 24 months after the last check. Web server access logs are deleted after 14 days.
(9) Your rights: You have the right of access (Art. 15 GDPR), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18) and to data portability (Art. 20), as well as the right to object to the processing on grounds relating to your particular situation (Art. 21 GDPR). Please contact the address in paragraph 1 for this purpose. The processing is not based on consent; there is therefore no right of withdrawal under Art. 7 (3) GDPR.
(10) Right to lodge a complaint: You may lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent authority is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.
(11) Automated decisions: No automated decision within the meaning of Art. 22 GDPR takes place. The grade awarded assesses the technical configuration of a domain as it is measurable from the outside; it does not entail a legal effect or a similarly significant impact on you.
Version 1.1 — as at 2 September 2026 — new § 7 with the information required by Art. 14 (1) and (2) GDPR for the holder of a checked domain. Measured on 2 September 2026, these rules carried none of thirteen of those items in full: controller, data protection officer, purposes and legal basis, legitimate interest, data subject rights, right to lodge a complaint and automated decisions were missing entirely; categories, recipients, storage period and source were present only as a description of the service for the person carrying out the check. The information in § 7 is taken from the privacy policy and is unchanged there.
Previously: Version 1.0 — as at 28 August 2026 (newly created in R-0: until then, the rule on having authority over the domain applied only to registered users)