RedScore.ai
All posts
Security Scanners

What is a Vercel security scanner?

A Vercel security scanner checks the public signals on your live domain: TLS, headers, DNS, email auth, and exposure. No repo access required.

1 min read · 2026-06-08 · RedScore Research Team

Quick answer

A Vercel security scanner checks the public posture of the domain your app runs on: TLS, headers, DNS, email authentication, and exposure. It reads what anyone on the internet can see. It does not audit your repo or Vercel project settings.

What does a Vercel security scanner check today?

It checks the domain in front of your app, not your Git repo. Certificate health, HTTPS behavior, security headers, DNS records, SPF and DMARC, cookie signals, and public exposure indicators.

Vercel makes deploys easy. That does not mean your public posture is automatically tight. Plenty of teams ship fast and only find out about weak headers or email spoofing risk when a customer asks.

RedScore runs a passive outside-in scan in about 60 seconds. No Vercel token, no repo upload, no invasive testing.

What is this not?

This is not a source-code audit. It is not an authenticated app test. It is not a review of your Vercel environment variables or project settings.

It is the first pass for what people can already check from the outside. That is usually enough to catch embarrassing public gaps before a demo or pilot.

How do I run a Vercel security scan?

  1. Deploy to a public hostname or custom domain.
  2. Go to /lookup and enter the production domain customers hit.
  3. Read the category grades and fix-first summary on the report.
  4. Fix the top failures.
  5. Rescan from /lookup after you ship fixes.

Book a pentest later if you need active testing. Start with the free outside-in scan first.

Frequently asked questions

Do I need to connect my Vercel account?

No. Paste the production hostname or custom domain. RedScore never touches your Vercel dashboard.

Does a Vercel security scanner read my repository?

No. Outside-in only. If a buyer or attacker cannot see it from the public web, this scan does not claim to find it.

Should I scan my *.vercel.app URL or my custom domain?

Start with the custom domain customers actually use. That is the hostname prospects and questionnaires care about.

What should I fix first after scanning?

TLS problems, missing security headers, weak email auth, and anything that looks publicly exposed. The report ranks them.

Run a free outside-in scan on your domain in about 60 seconds.

Scan domain