Sovereignty Scan

Whose infrastructure does a domain actually run on?

DNS, SPF chain, and ASN attribution - without a single HTTP request to the target site itself.

How the scan works

Resolve DNS & WHOIS

NS, MX, A, and AAAA records are resolved, and every IP is traced back to its autonomous system operator via the RIPE database - with curated corrections where CDN infrastructure fronting would otherwise misattribute jurisdiction, and IPv4/IPv6 paths checked independently for divergence.

Follow the SPF chain recursively

include:/redirect= references are resolved up to the RFC 7208 lookup limit - every leaf node yields its own provider and jurisdiction finding.

Weight jurisdiction

Each category gets a sensitivity weight (hosting/DNS 3, email 5) and a sovereignty value (EU/UK-CH/unclear/US), blended by the confidence of the attribution.

Also checked

DNSSEC status, the TLS certificate issuer jurisdiction, and reverse DNS are also checked and shown for context. Purely informational, no effect on the score.

Why without an HTTP request

The scan does not send a single HTTP request to the domain being checked. It evaluates exclusively public network signals: DNS records, the SPF chain, and ASN/WHOIS attribution. That is a deliberate scope decision compared to reference tools that additionally render the page and simulate consent banners - with the side effect that DNS and WHOIS signals cannot be blocked by bot protection or a cookie wall, unlike an HTML/script-based scan.

What the score is not

The grade is a risk indicator at the time of the query, not legal advice and not a binding GDPR compliance statement. It replaces neither a data protection impact assessment nor the judgment of a data protection officer. Anyone who believes a finding no longer matches their current setup can submit a statement via "Correct entry".