Skip to main content
Scan completion guide

Get the most complete result UNPWNED can verify

A partial result means some checks did not return authoritative evidence. Follow these four steps to verify ownership, run every available check, review any confirmed access control, and try the missing checks again.

One path, four steps

Complete the scan in this order

  1. Verify ownership

    Add the domain to your account and verify it by DNS TXT, HTML file, or meta tag. Verification authorizes the additional owner-only checks; it does not mark unanswered checks as successful.

    Open Domains
  2. Run the Deep Scan

    Select the verified domain and choose Deep Scan. This attempts every check available to verified owners. Free includes one lifetime Deep Scan; paid plans include unlimited Deep Scans.

    Start Deep Scan
  3. Review access only if needed

    If a fresh owner-authorized report confirms a WAF challenge, inspect the provider event for the scan time and identify the exact rule source before changing anything. Do not create a broad firewall bypass for UNPWNED's current shared cloud addresses.

    Choose my provider
  4. Run it again

    Re-run the same scan after access is configured. An official score and grade appear only when the required evidence completes. If coverage remains partial, the new report shows the remaining gaps.

    Run scan again

Explicit site policy

When robots.txt limits the scan

Public checks honor UNPWNED-Scanner Allow, Disallow, and Crawl-delay directives and use the wildcard group when no scanner-specific group exists. A scan backed by current exact domain verification and a recorded authorization treats crawler directives as advisory while keeping the fixed scanner rate, Retry-After, hostname scope, and non-destructive safety controls. The DNS-verified opt-out remains the authoritative way for a domain owner to block every UNPWNED scan.

Allow a full owner-authorized scan

Verify the domain in UNPWNED and accept the scan authorization. You do not need to weaken crawler rules for other bots.

Authorization never expands beyond the verified domain and its in-scope subdomains. Do not expose private or authenticated routes merely to satisfy a scan.

Check the request delay

Public scans follow a valid Crawl-delay up to the 60-second safety ceiling. Authorized verified scans use UNPWNED's fixed low-volume rate and still honor HTTP rate-limit responses and Retry-After.

Run the same authorized scan again. The new report will show whether a firewall, bot challenge, or another access control still limits coverage.

Read scanner policy

Provider shortcuts

Review edge access safely

Use the provider detected in your report. If no provider was detected, try a re-scan before changing any firewall settings; timeouts and upstream services can also cause incomplete coverage.

Cloudflare

Verify ownership with TXT, HTML file, or meta tag. Eligible paid users can then connect Cloudflare and separately approve the managed account-level rule for UNPWNED's published dedicated scanner IP. Read the account-wide warning before accepting. Never add a shared cloud address to an IP Access Allow rule.

Vercel Firewall

Confirm the gap came from Vercel system protection, then open /scanning-ips.json. Only when it reports egress: dedicated and allowlist_recommended: true may the verified domain owner manually add Vercel Firewall System Bypass for the single published dedicated IP and the exact domain. Never use a shared address or User-Agent. System Bypass does not override your custom rules, so keep them enabled. UNPWNED does not create Vercel firewall rules.

Scanner identity status

Signed identity is active for eligible owner-authorized requests. Cloudflare Web Bot Auth recognition is pending approval, so signatures alone do not guarantee verified-bot treatment. UNPWNED publishes an IP only when the dedicated proxy is configured; shared cloud addresses must never receive a firewall Allow rule.

Common questions

Does verification guarantee a grade?

No. It unlocks owner-only checks. A grade appears only after the required evidence completes.

Should I change my firewall first?

No. Re-scan after verification. Change access only when the report confirms a challenge and the provider event identifies the exact rule source.

Still partial?

Send the report link to support. We can identify whether the remaining gap is your WAF, authentication, an upstream service, or our scanner.

Ready to try again?

Run the scan after verification and any necessary, temporary access review. If the result is still partial, keep the protection enabled and send us the report link.