Research scanner
You found dot.bm in your access log.
We keep a picture of how Bermuda websites and mail domains are configured, so that when something is plainly broken or unsafe we can tell the owner. This page is what that involves. If you would rather we left your domain out of it, that takes one email and no explanation.
What we request
Five requests, spaced a second apart, no more than once a week. Everything below is something your server already publishes to anyone who asks for it.
DNS records
MX, SPF, DKIM, DMARC, MTA-STS, TLS-RPT and the address records for the domain. These are public lookups answered by the internet name system, not by your server.
The front page
One request for the home page over HTTPS, the same request any browser makes.
Port 80
One request to see whether plain HTTP redirects to HTTPS.
A TLS handshake
One connection that offers only older protocol versions, to see whether they are still accepted.
security.txt
One request for /.well-known/security.txt, the standard location published for exactly this purpose.
Our requests identify themselves. The user agent is
dot.bm-research and it carries the address of this page.
What we never do
This is the part that matters, so it is written as a commitment rather than a description. Reading what a server publishes is not the same as testing it, and we only do the first.
Guessing addresses
We do not look for admin pages, login forms, backup files, readme files or anything else by guessing at addresses. If your front page does not link to it, we do not ask for it.
Testing for weaknesses
We send no unusual input, no payloads and no automated attempts of any kind. Nothing we send is designed to make software behave unexpectedly.
Logging in
We do not attempt to authenticate, and we do not use credentials found anywhere.
Scanning ports
We connect to the two ports a website already answers on. We do not survey anything else.
Submitting forms
We do not fill in or submit anything on your site.
We do carry out deeper testing, but only for a client who has asked for it in writing, against systems they own, on a date we have agreed. That work has nothing to do with this scanner and never runs from it.
What we record
Technical facts about the domain: which records exist, which headers are set, what certificate is served, what the page says it was built with. We keep the date we observed each one, because a finding from three weeks ago may already be fixed.
We do not collect personal information. We do not record who works at a company, and we do not build profiles of people. Where we need a way to reach an owner we use a published business address such as info@ or a phone number on the site, and nothing more.
We do not publish what we find about your domain, sell it, or pass it to anyone else. If something is wrong with your domain, the only people we discuss it with are you.
We do publish counts. How many .bm domains have a setting and how many do not, island-wide, with no domain named and none singled out. The September 2026 study is the whole of it, and your domain is one of the numbers in it and nothing else.
How to be excluded
Email [email protected] with the domain name. We remove it and it stays removed. You do not have to say why, you do not have to prove you own it, and we will not ask you to reconsider.
If you would rather block us at your end, refuse the user agent
dot.bm-research. We will not work around it.
Did we contact you about your domain?
Then something we saw was worth a message, and it is in that email. There is no charge for it and nothing you need to buy. If you want the rest of what we saw for your domain, ask and we will send it.
Get in touch ↗