Security & Responsible Disclosure

We advise others on domain-based risk, so we hold this site to the same standard — and we want to hear from you if you find a weakness.

How we secure this site

domainhotlists.com is served over HTTPS with HSTS, a strict Content-Security-Policy, and modern isolation headers (frame-ancestors, cross-origin policies). We run no third-party advertising or tracking scripts; analytics, if ever enabled, load only after you consent. We operate no web contact form and store no enquiry data in a website database — email reaches us directly.

Reporting a vulnerability

If you believe you have found a security vulnerability in this website, we want to hear from you. Email [email protected] with:

  • a description of the issue and where you found it;
  • the steps needed to reproduce it; and
  • the potential impact as you see it.

Please give us a reasonable chance to investigate and fix the issue before disclosing it publicly. We will acknowledge your report, keep you updated, and credit you if you would like once it is resolved.

Please do not

  • Access, modify or delete data that is not yours, or degrade the service for others (no denial-of-service or spam testing).
  • Use social engineering, phishing, or physical attacks against our people or infrastructure.
  • Run high-volume automated scans.

Safe harbor

If you make a good-faith effort to follow this policy, we will treat your research as authorised, and we will not pursue or support legal action against you for it. If you are unsure whether an action is acceptable, ask first at [email protected].

A machine-readable version of this contact is published at /.well-known/security.txt.