Scanner IP addresses
Every scan originates from a small set of reserved static addresses. Allowlist them in your WAF, IDS, and rate limiters so scans are not throttled into a misleading result.
Addresses are published here once infrastructure is provisioned, and are also available as JSON at /scanner-ips.json for automated allowlisting.
How we scan
- TLS handshakes only. We never send application data or attempt exploitation.
- Probes run sequentially per host with jittered gaps, so traffic looks like ordinary sporadic client activity rather than a burst scan.
- Roughly 16 handshakes per host. We do not enumerate every cipher suite in existence.
- We never complete a handshake, and never reuse a connection.
Full details are in our scanning policy. If our traffic is causing a problem, contact abuse@secretspan.com and we will stop immediately.