Security

Found something? Tell us first.

RelayDNS sits between products and their customers' DNS, so a flaw here could matter to people who have never heard of us. We would rather hear it from you.

security@relaydns.dev
  1. 1

    You email us

    Write to security@relaydns.dev with what you found.

  2. 2

    We acknowledge it

    Within three working days, from a person.

  3. 3

    We reproduce and fix

    We tell you what we found and when it is fixed.

What to send

Enough to reproduce it. Nothing more.

  • What you found, and what an attacker could do with it
  • The URL, endpoint or file involved
  • Steps to reproduce, with requests and responses where you have them
  • How to reach you for follow up questions

In scope

Anything we run. Not what our customers run.

  • relaydns.dev

    This site and the dashboard

  • The API

    /v1, the widget endpoints and provider callbacks

  • relaydns.js

    The widget script your customers load

  • Our templates

    Domain Connect templates and request signing

A product that uses RelayDNS is its own company. Report issues in it to them.

Ground rules

Test like it is yours. Because it is someone's.

  • Only test against domains and accounts you control.
  • Do not access, change or keep anyone else's data. Stop at proof.
  • No load or denial of service testing.
  • Give us a chance to fix it before you tell anyone else.

Plainly

There is no paid bug bounty. Every report is read and answered by a person. We have not had an independent penetration test yet, which is one more reason your report matters.

How RelayDNS is secured