Scanning
Rescans and disputes
Last updated: August 6, 2026
ComplianceLayer reports describe what a domain's public configuration looked like at the moment it was scanned. Configurations change, and external observation has limits. If a report about your organization is out of date or wrong, this page explains how to get it corrected.
You do not need a ComplianceLayer account to use any of the routes below, and none of them cost anything.
1. Request a rescan
Use this when the report was accurate at the time but you have since changed the configuration — you published a DMARC record, renewed a certificate, closed a port.
Email support@compliancelayer.net with the subject line Rescan request and include:
- The domain
- The report ID or verification code, if you have one (it is printed on every PDF report and shown on the verification page)
- What changed, so we know what to look for
A rescan produces a new report with a new timestamp. It does not delete or alter the earlier report — reports are bound to the moment they were issued, and rewriting history would make every report we have issued less trustworthy. The new report supersedes the old one.
2. Dispute a finding
Use this when you believe a finding is wrong on its own terms — the check misread your configuration, the control it flags does not apply to this host, or the severity is misjudged.
Email support@compliancelayer.net with the subject line Finding dispute and include:
- The domain and the report ID or verification code
- The specific finding, quoted from the report
- Why you believe it is incorrect, and any evidence you can share — a
digoutput, a certificate chain, a header dump
We will re-run the relevant check and tell you what we find. If the finding was wrong, we correct it, reissue the report, and — where the cause was a defect in a scan module rather than a transient condition — fix the module so the same error does not recur for anyone else.
If we conclude the finding was correct, we will say so and explain the evidence it rests on. We will not withdraw an accurate finding on request.
3. Object to being scanned
If you own a domain and do not want it scanned through ComplianceLayer at all, we will add it to a blocklist that our platform refuses to scan. A blocked domain cannot be scanned by any customer, on any plan, going forward.
Email abuse@compliancelayer.net with the subject line Scan exclusion request, from an address at the domain in question or from an address we can otherwise tie to the domain's registrant, and include:
- The domain or domains you want blocked
- Evidence that you are authorized to make the request — a reply from the WHOIS or registrar contact, or a DNS TXT record we can verify
We ask for verification only to stop one party from blocking another party's domain.
If you believe your infrastructure has been scanned through ComplianceLayer without authorization, say so in the same email. Scanning without the domain owner's authorization violates our Acceptable Use Policy and we suspend accounts that do it.
4. What to expect
We acknowledge every request to the routes above and review each one.
ComplianceLayer is a small team. If a request needs a scan module changed rather than a record corrected, the fix may take longer than the acknowledgment — we will tell you where it stands rather than leave you waiting.
5. What this page is not
ComplianceLayer reports describe externally observable configuration. They are not an audit, a certification, or a determination of whether any organization is secure, compliant, or insurable. A report is evidence for a human to weigh, not a verdict. Nothing on this page changes that, and disputing a finding is not a route to a different verdict — only to a more accurate observation.
For how scanning works and what our scanners do and do not do, see About ComplianceLayer scanning. For privacy requests about personal data, see our Privacy Policy.
6. Contact
Rescans and disputed findings: support@compliancelayer.net
Scan exclusion and abuse: abuse@compliancelayer.net
Legal: legal@compliancelayer.net