Security
Found something? Tell us first.
RelayDNS sits between products and their customers' DNS, so a flaw here could matter to people who have never heard of us. We would rather hear it from you.
security@relaydns.dev- 1
You email us
Write to security@relaydns.dev with what you found.
- 2
We acknowledge it
Within three working days, from a person.
- 3
We reproduce and fix
We tell you what we found and when it is fixed.
What to send
Enough to reproduce it. Nothing more.
- What you found, and what an attacker could do with it
- The URL, endpoint or file involved
- Steps to reproduce, with requests and responses where you have them
- How to reach you for follow up questions
In scope
Anything we run. Not what our customers run.
relaydns.dev
This site and the dashboard
The API
/v1, the widget endpoints and provider callbacks
relaydns.js
The widget script your customers load
Our templates
Domain Connect templates and request signing
A product that uses RelayDNS is its own company. Report issues in it to them.
Ground rules
Test like it is yours. Because it is someone's.
- Only test against domains and accounts you control.
- Do not access, change or keep anyone else's data. Stop at proof.
- No load or denial of service testing.
- Give us a chance to fix it before you tell anyone else.
Plainly
There is no paid bug bounty. Every report is read and answered by a person. We have not had an independent penetration test yet, which is one more reason your report matters.