// how_it_works

How QuackScan Works

A transparent, step-by-step security assessment process. You control the depth, and we show you exactly what we find.

01

Enter your domain

Type your domain (e.g., yourapp.com) and choose what to assess. Basic assessments start immediately with no setup required.

02

Choose assessment depth

Select how thorough the assessment should be. Deeper levels require domain ownership verification.

Basic
no verification needed

Read-only checks on publicly accessible endpoints, headers, SSL, and exposed services.

Standard
no verification needed

Infrastructure analysis, technology detection, and frontend secret scanning. Still read-only.

Deep Assessment
dns verification required

Active vulnerability scanning, default credential testing, and parameter fuzzing. Requires you to prove domain ownership first.

03

Review free preview

See all findings with severity ratings visible. Detailed evidence and remediation steps are blurred in the preview. This lets you evaluate the value before paying.

See a demo report
04

Unlock full report — $25

Pay one-time to unlock all evidence, step-by-step remediation instructions, and a professional PDF report delivered to your email. No subscriptions.

// domain_verification

Domain Verification

Deep assessments (active scanning, credential testing, fuzzing) require you to prove domain ownership by adding a DNS TXT record. This ensures assessments only run on systems you own.

How to verify your domain

1
Start a deep assessment

Select any deep scan option (nuclei scanning, credential testing, or fuzzing). You'll be prompted to verify your domain.

2
Add a DNS TXT record

Add the following TXT record to your domain's DNS settings:

Type:TXT
Name:_quackscan.yourdomain.com
Value:quackscan-verify=your-unique-token
3
Click verify

We check the DNS record in real-time. Once verified, all deep assessment options are unlocked for that domain. Verification persists across sessions.

Why we require verification
Active security testing should only be performed on systems you own or have explicit authorization to test. DNS verification is the industry-standard method to prove domain ownership, used by services like Google Search Console and certificate authorities.