Skip to content
whack.sh whack.sh
How it works Features Pricing FAQ News Sign in

Terms of Service

Last updated: July 2, 2026

These Terms govern your use of whack.sh (the “Service”), a defensive security tool that loads a URL through multiple network vantage points (datacenter, residential, mobile, and bring-your-own egress) and diffs the results to expose cloaking, redirect chains, and hidden payloads. whack.sh is a legitimate security-research and threat-investigation service operated for defenders. It is not an anonymity, attack, evasion, or abuse tool. By creating an account or using the Service you agree to these Terms and the Acceptable Use Policy below; if you do not agree, do not use the Service.

1. Who may use the Service

The Service is intended solely for authorized defenders — security researchers, incident responders, fraud and abuse teams, brand-protection and threat-intelligence professionals, and similar — investigating threats they are authorized to investigate. You represent that you are using the Service for these purposes, on your own behalf or for an organization you are authorized to represent, and that you are not a sanctioned party or barred from using the Service under applicable law.

2. Acceptable Use Policy

You agree to:

  • Submit only URLs you are authorized to investigate, and use results solely for lawful, defensive, and research purposes.
  • Not use the Service to attack, overload, gain unauthorized access to, or disrupt any system, or to harvest data you are not entitled to.
  • Not resell or abuse egress capacity (residential, mobile, or your enrolled BYO device), and not route traffic through any IP, network, or device you are not authorized to use.
  • Comply with all applicable laws and these Terms.

Prohibited uses. You must not use the Service, directly or indirectly, to:

  • Develop, test, tune, validate, operate, or evade the detection of any cloaking system, traffic-distribution system (TDS), doorway, malware, scam, phishing, fraud, malvertising, or other malicious or deceptive infrastructure or campaign;
  • Assess, measure, or improve your or another party’s ability to bypass security controls, threat detection, ad-network or platform policy enforcement, or abuse defenses (including ours);
  • Reverse engineer, probe, scrape, or attempt to derive the Service’s detection methods, signals, signatures, scoring, thresholds, or vantage-point infrastructure;
  • Facilitate, conceal, or further any unlawful, infringing, or harmful activity, or any activity that would cause the Service’s egress IPs or partners to be implicated in such activity;
  • Scan government, military, or financial-sector targets, or other sensitive or regulated targets, except where you are expressly authorized and we have enabled such use for your account in writing.

A suspected-malware payload is retained only as the served file the scan already received in the browser — never separately re-fetched. Captured samples are neutralized at rest, handled in an isolated environment, retained server-side for detection only, never executed, and never served for download from whack.sh. Confirmed-malicious samples are contributed to public malware-research platforms as described in §8.

3. Automated assessments — opinion, not accusation

All verdicts, scores, classifications, chains, and indicators produced by the Service are generated automatically by software, reflect observed behavior at a particular time from particular vantage points, and are inherently incomplete and may be inaccurate or out of date. They are statements of technical opinion and observation, not statements of fact, legal conclusions, or accusations of wrongdoing against any person or organization. Any plain-English or AI-generated summary is a convenience restatement of these same automated signals — likewise opinion and observation, not a legal determination — and does not name or make claims about who operates any site.

The appearance of any domain, host, IP address, network, ASN, certificate, brand, or organization in a result does not mean that party created, authorized, endorsed, controls, or is responsible for any observed content. Content on the modern web is frequently served by third parties — advertisers, affiliate and ad networks, traffic brokers, redirect chains, compromised infrastructure, parked-domain monetizers, or downstream actors — often without the knowledge or control of the registrant, host, or network operator named in a result. You agree not to represent the Service’s output as a definitive determination of any party’s conduct, and you are solely responsible for any conclusions you draw, share, or publish from it and for ensuring any such use is lawful.

4. Accounts & API keys

You are responsible for all activity under your account and API keys. Keep credentials secret and notify us promptly of any compromise. One account per person or organization unless otherwise agreed in writing.

5. Credits, plans & billing

Datacenter scans are offered on a free tier (the first 5 MB of each scan is included at no charge; beyond that a small per-MB overage applies) subject to rate limits; a datacenter leg you pin to a specific country routes through a paid egress pool at the same price. Residential, mobile, and certain premium egress you request consume credits. Paid egress is metered — a base credit per leg covers an included bandwidth allowance, then a small per-MB overage; the bandwidth cap you select bounds the maximum credits a scan can consume, and scans that do not reach the target (offline or unreachable URLs) are not charged. Separately, and at our option and expense, a sampled portion of free datacenter scans may also be run through a residential vantage point so we can compare what a site serves to different visitors; this comparison leg is never billed to you and is not counted against any limit, and we retain only whether the results diverged (which we may surface as a prompt to run a full multi-egress scan). Credits and paid plans are described on pricing; prices, limits, and bonuses may change. Monthly subscription credits expire at the end of each period and do not roll over; purchased credits are non-refundable except where required by law. Suspension or termination for a violation may result in forfeiture of remaining credits without refund. Payments for credits and subscriptions are processed by PayPal; your card and payment details are entered on and handled by PayPal, not whack.sh, and are subject to PayPal’s own terms.

6. Bring-your-own egress (BYO)

If you enroll a device as a BYO egress, you confirm you own or are authorized to use that device and its network, and you are responsible for all traffic routed through it. You may disable or delete a BYO agent at any time from your account.

7. Brand Protection

Brand Protection is an optional monitoring service for verified stakeholders. To monitor a domain you must prove control of it via a DNS-TXT challenge; to monitor a brand term, it must correspond to a domain you have verified. You represent and warrant that you own or are authorized to monitor each domain and brand term you register, and you may not use the feature to surveil third parties. When our scanners observe a monitored domain — or a lookalike of your monitored brand — participating in a malicious chain (for example a redirect/TDS hop, malware, or phishing), we send you a private, informational alert by email and/or webhook. Alerts are behavioral observations, not accusations or legal advice; we do not perform takedowns or enforcement, and we do not publish them. Where a finding is observed in another party’s scan, an alert shares only technical indicators and never that party’s report or identity. Certain plans include a number of monitored assets; additional verified assets are a paid add-on billed per asset per month from your credit balance (see your account for current inclusions and pricing). Only verified assets are billed; pending, failed, or removed assets are not.

8. Threat intelligence & sample contribution

When a scan captures a file that is confirmed malicious, whack.sh contributes that file, its SHA-256 hash and basic file attributes (type, size, tags) to public malware-research platforms — currently VirusTotal, abuse.ch MalwareBazaar and AlienVault OTX. This is an integral part of the Service: shared samples let the wider security community detect and block the same threat. Contribution is automatic for confirmed-malicious samples; content that is benign, unconfirmed or inconclusive is never submitted.

What is shared: the malicious file and its hashes/metadata. What is never shared: your identity, your account details, or the URL you scanned. Samples are stored defanged at rest and are never served for download from whack.sh itself.

You represent that you are entitled to submit the URLs you scan and that content captured from them may be contributed as described above. Note that once a sample is published to a third-party platform it is retained under that platform’s own policy and cannot be recalled by us. If you require contribution to be disabled for your scans (for example under an enterprise or private-handling arrangement), contact us.

9. Service “as is”; no warranty

Scan results are best-effort and provided for informational purposes only. They are not a guarantee that a URL is safe or malicious, and are not legal, financial, or professional security advice. The Service is provided “as is” and “as available,” without warranties of any kind, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement.

10. Limitation of liability

To the maximum extent permitted by law, whack.sh and its operators are not liable for any indirect, incidental, special, consequential, or exemplary damages, or for any loss of profits, data, goodwill, or business, arising from or relating to the Service or these Terms. Our aggregate liability for all claims is limited to the greater of the amount you paid us in the three months preceding the claim, or US$100.

11. Indemnification

You will defend, indemnify, and hold harmless whack.sh and its operators from and against any claims, liabilities, damages, losses, and expenses (including reasonable legal fees) arising out of or related to: (a) your use of the Service; (b) URLs or content you submit; (c) your use, sharing, or publication of results; or (d) your violation of these Terms, the Acceptable Use Policy, or any law or third-party right.

12. Suspension & termination

We may suspend, restrict, throttle, reduce the detail of output to, or terminate any account or access, at any time, with or without notice and with or without cause, in our sole discretion — including where we suspect use inconsistent with these Terms or the Acceptable Use Policy, use to develop or evade detection of malicious infrastructure, abuse, a risk to the Service, our egress partners, or others, or where we deem it appropriate to comply with law or a request from authorities. We will not be liable to you or to any third party for any suspension, restriction, reduction, or termination. You may stop using the Service and request account deletion at any time via contact.

13. Reservation of rights

We may refuse, decline, or discontinue service to anyone for any lawful reason; investigate suspected violations; and preserve and disclose information where we believe in good faith it is necessary to comply with law, enforce these Terms, or protect the Service, our users, or the public.

14. Changes; governing terms

We may update these Terms; material changes are reflected by the “last updated” date, and continued use after changes constitutes acceptance. If any provision is held unenforceable, the remainder stays in effect. These Terms are the entire agreement between you and whack.sh regarding the Service.

15. Contact

Questions about these Terms? Get in touch.

Product

Multi-source scanner Datacenter geo scanner How it works Features Use cases Pricing

Developers

API docs FAQ

Trust & transparency

Sample of the week Captured malware Report a mistake

Company & legal

About News Contact Terms Privacy
© 2026 whack.sh — multi-egress URL threat scanning Owned and operated by Tuxxin LLC · State of Florida, United States

Organizations, domains, IPs, ASNs & software stacks named in results are flagged by automated analysis from a documented history of observed cloaking and/or malware distribution — not a statement of fact about any party. Flagged in error? Request removal or re-review →