Contact
dotvitals is a small project. The addresses below reach the people running it directly — there is no support queue and no first-line filter.
Last updated
General contact
For anything that is not abuse, a correction request or a security report — questions about a result, feedback, partnership or advertising enquiries, or anything else — write to contact@dotvitals.com.
Please include the URL of the page you are asking about and, if relevant, the target you scanned and roughly when you scanned it; scan results are not tied to an account, so a URL or a scan id is the fastest way to find the right record. Scan records are deleted after 30 days, so a question about a specific scan has to reach us inside that window.
Abuse reports and scanner opt-out
abuse@dotvitals.com is the published abuse contact for dotvitals' scanning traffic. It is the right address if dotvitals has probed a domain or server you own and you want to ask what happened, complain about it, or have it stop.
Our active probes come from 209.71.105.67 and 2a09:8280:e601:1:0:190:4889:0, in Amsterdam, Netherlands, and every request carries the user agent "dotvitals/1.0 (+https://www.dotvitals.com/scanner/)". If what you are seeing matches none of those, it is not us — but tell us anyway, because somebody claiming to be us matters to us too.
- Include the domain, the approximate time of the probe, and, if you have it, the scan id shown on any result page for that scan.
- Say clearly whether you want an explanation, an opt-out, or both.
The scanner policy page explains what each probe actually does and how the opt-out works, including how we confirm you control the domain before acting on the request.
If you believe dotvitals is being used to abuse a third party — for example as a relay for scanning targets someone does not control — report it to the same address with as much detail as you can provide.
Corrections and takedown requests
If a page contains factually wrong information, or if you want a shared report link or a scan record associated with your own use of the tool removed, write to contact@dotvitals.com with the specific URL or scan id and what you want changed or removed.
There is nothing to take down from the email header analyzer: it stores nothing, so there is no record of a header analysis to delete.
Requests relating to personal data and data-subject rights are handled under the privacy policy; the same address is the starting point for those requests too.
Security reports
To report a security vulnerability in dotvitals itself (the site, the API, the scanners, or the infrastructure that runs them) — as opposed to a finding dotvitals reports about a third-party domain — see /.well-known/security.txt for the current reporting contact, scope and any disclosure timeline.
You can also write directly to security@dotvitals.com. Please do not test findings against third-party domains without their permission, and please do not publicly disclose a report before there has been a chance to address it.
Response times
This is best-effort, not a service-level agreement. There is no dedicated support team behind these addresses.
- Security reports are the priority and are typically acknowledged fastest.
- Abuse reports and opt-out requests are handled promptly because they affect real infrastructure, but "promptly" is not a guaranteed number of hours.
- General contact and corrections are handled as time allows, which can be several days.
If something is urgent — an active incident, or a scan actively causing harm — say so clearly in the subject line.
What not to send
Do not send passwords, API keys, full credit card numbers or other secrets to any of the addresses above; none of them are set up to handle that safely. If a report requires sharing something sensitive, ask first and a secure method will be arranged.
Do not paste raw email headers into a message to us either. Use the header analyzer, which runs in your own browser, rather than sending somebody's correspondence to a mailbox.