notra·
Abuse

Report a scan you didn’t authorize.

Notra requires proof of domain ownership before any active probing. If you believe our scanner reached a site you control without that authorization, tell us and we’ll act quickly.

Email abuse@notra.audit with the details below. Urgent, in-progress activity is triaged ahead of everything else.

What to include

The affected domain or IP, the approximate date and time window, and anything from your logs that identifies the traffic, a source IP, a User-Agent (ours contains notra-scan for the free scorecard or notra-agent for a paid audit, always with abuse@notra.audit in it), or specific request paths. Proof that you control the asset helps us act without delay.

What happens next

We locate the scan, suspend it, and identify the account behind it. Unauthorized scanning is a violation of our terms, and confirmed abuse results in the account being blocked. We’ll confirm back to you once the activity is stopped.

How we prevent it

Ownership is verified with a DNS TXT record or an uploaded file token before a deep audit runs, probes are non-destructive by default, and money-movement endpoints are never touched without explicit consent. Abuse reporting is the backstop, not the first line of defence.

Confirmed abuse leads to account suspension under our terms of service. Reporting a vulnerability in Notra itself instead? That goes to our security team, and for anything else there’s the general contact page.

Every scan carries our name.

Each scan's User-Agent carries a public abuse contact. We don't hide who's probing your site — report anything that looks off.

Contact us Security & disclosure