Questions

Can I use ClickScan yet?

Yes. ClickScan is live and open to everyone — no invitation, no waiting list. Create an account with your email address, and new accounts get free starter credits so the first check costs nothing.

Who is this for?

Anyone with something exposed online: freelancers and agencies checking clients, startups and SMEs without a security team, enterprise teams wanting lightweight external monitoring, and bug-bounty researchers doing fast recon on authorized targets.

Do I need to be technical?

No. Reports are written in plain language — what you have, how serious it is, and exactly what to do. No CVSS jargon in the main view, and where a fix means publishing a DNS record we write the record out for you, already filled in with your domain.

What's an "organization"?

A flexible group of assets — not necessarily your company. Create one per client, project, brand or environment, invite the right people with roles, and share assets, scans and reports within it. It's included by default.

How do I sign in?

With a one-time code emailed to you. There are no passwords to remember or reset.

What does it cost?

Pay-as-you-go credits — no subscription and no per-seat fee. New accounts get free starter credits; recurring scans are discounted; PDF exports and higher volumes come with paid credits. The current packages and prices are in the app.

Do my credits expire?

Credits you pay for don't expire. Free credits — starter, referral and goodwill grants — expire twelve months after they're granted, and are always spent before the ones you paid for. We warn you before any expire.

Can I scan any website?

Passive checks (like TLS and email) run on public data. For active checks you confirm you're authorized to test the target; for certain checks — the live spoofing test, which delivers a real forged message; the port scan, which connects to your host; and the breach check, which looks up records about a person — we also ask you to prove the asset is yours, using whichever suits it: a DNS TXT record, a file at /.well-known/, a code emailed to an address at the domain, a callback from the IP, or reverse DNS. Exactly which checks require proof is subject to change as we add them.

Which IP addresses do your scans come from?

A small, published set, kept current at clickscan.ai/scanner/ips.txt. If your firewall, WAF or hosting provider blocks unknown scanners, allow those addresses and your scans complete instead of timing out. Read them from that page rather than copying them into a document — we add capacity as the platform grows, and a copy made today goes stale silently. You can confirm a scanner really is us before allowing anything: each address has forward-confirmed reverse DNS, so it resolves to a name like egress1.clickscan.ai and that name resolves back to the same address — both directions agree, which an impersonator cannot arrange. Customers get the per-check detail in the help centre. We never need an account, an agent, a VPN, or any inbound access beyond the service being checked.

What happens if a scan fails, or finds nothing to test?

You get the credits back. A scan that fails is refunded automatically, and a check that couldn't test anything — a spoofing test against a domain that receives no email, say — is graded "not applicable" and refunded rather than being passed off as a good result.

Can I put my own logo on the reports?

Yes. Agencies and consultants can brand the PDF reports per workspace with their own logo and colour. Submissions are reviewed before they go live, and a small "powered by ClickScan" line stays on the page.

Can I get the lookalike domains into my own tools?

Yes — as a STIX 2.1 bundle or as YARA rules, for a whole scan or for one domain. Only what is worth acting on is exported: parked domains, another company's legitimate brand protection, findings we could not confirm and anything you have told us is yours are all left out, because an indicator ends up in a blocklist with nobody reading it first.

What if a "lookalike" domain is actually mine?

Tell us, and we stop treating it as an impersonation of your brand — on that report and every future one. Our check decides ownership from your DNS, so it recognises a defensive registration sitting on your own nameservers and misses a subsidiary registered elsewhere. This corrects the check rather than hiding what it said, so it does move the grade; withdrawing it moves the grade back, and the record of what you declared is kept either way.

Are there limits on how much I can scan?

Light ones, to keep scans reliable and gentle on the systems you test: by default up to 2 scans against the same host at once, and up to 200 queued across your account. Beyond that you are limited only by your credit balance. Trying to bypass these limits — or pointing the scanners at our own systems — is not allowed.