HREN
MajhenLabs

About this scanner

If you reached this page from a log entry or an abuse report, this explains who we are and why our address contacted your domain.

Who operates this

This scanner is operated by MajhenLabs (Robert Majhen), an independent security consultancy. It runs from a single server whose outbound address is:

178.104.22.81

Forward and reverse DNS for that address match, and all scanning originates from it. If you saw a different address claiming to be us, it was not us.

Identifying us in your logs

Every HTTP request we send carries this exact User-Agent, which links back to this page:

MajhenLabs-Scanner/1.0 (+https://scan.majhenlabs.com/abuse)

We do not spoof browser User-Agents, we do not rotate source addresses, and we do not attempt to evade rate limiting or blocking. If you block us, we stay blocked.

What a scan does

The automated scan is a light, read-only assessment of publicly accessible information only. In a single run it may:

Volume, in concrete numbers

A complete run against one domain is:

For comparison, an off-the-shelf vulnerability scanner sends several thousand requests against a single host. We deliberately run about two orders of magnitude below that, because the goal is a report for the site owner, not coverage.

The same domain is not re-scanned on repeat: results are cached and a repeated request returns the stored report instead of touching your server again. Requests are additionally rate-limited per requester, per source address, and per target domain.

What a scan never does

On whose request

A scan is not started at random. Before any scan runs, the person requesting it must receive a one-time code sent to an email address on the domain being scanned and enter it back. In other words, a scan of your domain means someone who could receive mail at your domain asked for it.

We keep a record of every scan: the target domain, the timestamp, and the verified email address that requested it. If you are the domain owner or its hosting provider, tell us the domain and the date and we will tell you which address requested that scan.

This email check is a good-faith signal, not a claim of full authorization. Any deeper, authenticated, or intrusive testing is never automated and is only ever performed under separate, written authorization.

Do not want to be scanned?

Email us and we will add your domain and any address you name to a permanent do-not-scan list. Please include the domain and, if you have it, the date and time from your logs so we can confirm the match.

Contact: robert@majhenlabs.com

For hosting and abuse teams

If you are handling an abuse report about the address above, please contact us directly at robert@majhenlabs.com. We respond quickly, we keep records of what was scanned and on whose request, and we will stop scanning any domain on request without argument.