Skip to main content
UNPWNED
Scan completion guide

Get the most complete result UNPWNED can verify

A partial result means some checks did not return authoritative evidence. Follow these four steps to verify ownership, prepare the dedicated scanner identity, run every available check, and try the missing checks again.

The shortest safe path

Four actions to reach the deepest coverage

If the domain is not verified yet, verify it first. Already verified? Continue to the scanner IP shown in its domain card when the dedicated scan lane is active.

  1. 01

    Verify the domain

    Prove ownership from the Domains screen.

  2. 02

    Copy the scanner IP

    Use only the address shown in the verified domain card.

  3. 03

    Authorize the scanner IP

    Scope the allow rule to the verified hostname and keep every other protection enabled.

  4. 04

    Run Deep Scan again

    The new report shows what completed and what still needs attention.

Never expose private routes, remove authentication, or allow a shared cloud address just to complete a scan.

Open domains and scanner access

One path, four steps

Complete the scan in this order

  1. Verify ownership

    Add the domain to your account and verify it by DNS TXT, HTML file, or meta tag. Verification authorizes the additional owner-only checks; it does not mark unanswered checks as successful.

    Open Domains
  2. Prepare scanner access

    Open the verified domain card to see UNPWNED's current dedicated IP and scanner identity. If your firewall, WAF or bot protection normally blocks automation, add the narrow provider-specific rule before scanning. Keep every other protection enabled.

    Prepare a verified domain
  3. Authorize and run the Deep Scan

    Select the verified domain, choose Deep Scan, and confirm the limited active-testing scope. This attempts every check available to verified owners. Free includes one lifetime Deep Scan; paid plans include unlimited Deep Scans.

    Start Deep Scan
  4. Run it again

    Re-run the same scan after access is configured. An official score and grade appear only when the required evidence completes. If coverage remains partial, the new report shows the remaining gaps.

    Run scan again

Explicit site policy

When robots.txt limits the scan

Public checks honor UNPWNED-Scanner Allow, Disallow, and Crawl-delay directives and use the wildcard group when no scanner-specific group exists. A scan backed by current exact domain verification and a recorded authorization treats crawler directives as advisory while keeping the fixed scanner rate, Retry-After, hostname scope, and non-destructive safety controls. The DNS-verified opt-out remains the authoritative way for a domain owner to block every UNPWNED scan.

Allow a full owner-authorized scan

Verify the domain in UNPWNED and accept the scan authorization. You do not need to weaken crawler rules for other bots.

Authorization never expands beyond the verified domain and its in-scope subdomains. Do not expose private or authenticated routes merely to satisfy a scan.

Check the request delay

Public scans follow a valid Crawl-delay up to the 60-second safety ceiling. Authorized verified scans use UNPWNED's fixed low-volume rate and still honor HTTP rate-limit responses and Retry-After.

Run the same authorized scan again. The new report will show whether a firewall, bot challenge, or another access control still limits coverage.

Read scanner policy

Provider shortcuts

Review edge access safely

Use the provider detected in your report. If no provider was detected, try a re-scan before changing any firewall settings; timeouts and upstream services can also cause incomplete coverage. If you already know which protection layer serves your verified domain, you can prepare its narrow scanner rule before the first Deep Scan.

Cloudflare

Verify ownership with TXT, HTML file, or meta tag. Eligible paid users can then connect Cloudflare and separately approve the managed account-level rule for UNPWNED's published dedicated scanner IP. Read the account-wide warning before accepting. Never add a shared cloud address to an IP Access Allow rule.

Vercel Firewall

Confirm the gap came from Vercel system protection, then open /scanning-ips.json. Only when it reports egress: dedicated and allowlist_recommended: true may the verified domain owner manually add Vercel Firewall System Bypass for the single published dedicated IP and the exact domain. Never use a shared address or User-Agent. System Bypass does not override your custom rules, so keep them enabled. UNPWNED does not create Vercel firewall rules.

Railway

Railway protects its network edge but does not provide an application-layer WAF. Do not change Public Networking, DNS, ports, or expose a private service just for a scan. If Cloudflare proxies the custom domain, use the Cloudflare steps. Otherwise inspect your application logs and middleware. Only if your own IP, rate-limit, or bot rule rejects UNPWNED should you add a narrow server-side exception for the published dedicated IP and exact hostname. Keep authentication required.

AWS WAF

Confirm the WAF caused the gap before changing it. If a one-time exception is required, scope it to the exact domain, methods, and scan window, monitor it, and remove it immediately after the scan. Use only the dedicated scanner IP published by UNPWNED. Shared scanner IPs are never suitable for an Allow rule.

Any other provider

  1. 1. Check the CDN, WAF, reverse-proxy, and application logs for the published scanner IP.
  2. 2. Confirm the rejection came from that layer, not from authentication, an upstream outage, or a response limit.
  3. 3. If needed, allow only the dedicated IP for the exact verified hostname. Never trust the User-Agent by itself.
  4. 4. Keep authentication, private routes, global security rules, and protections for every other source unchanged.

Scanner identity status

Signed identity is active for eligible owner-authorized requests. Cloudflare Web Bot Auth recognition is pending approval, so signatures alone do not guarantee verified-bot treatment. UNPWNED publishes an IP only when the dedicated proxy is configured; shared cloud addresses must never receive a firewall Allow rule.

Common questions

Does verification guarantee a grade?

No. It unlocks owner-only checks. A grade appears only after the required evidence completes.

Should I prepare firewall access first?

If the verified domain uses a WAF or bot protection, prepare the narrow provider-specific rule with UNPWNED's published dedicated identity before the first Deep Scan. Never disable the wider protection.

Still partial?

Send the report link to support. We can identify whether the remaining gap is your WAF, authentication, an upstream service, or our scanner.

Ready to try again?

Run the scan after verification and any necessary, temporary access review. If the result is still partial, keep the protection enabled and send us the report link.