> ## Documentation Index
> Fetch the complete documentation index at: https://docs.validate.al/llms.txt
> Use this file to discover all available pages before exploring further.

# Scan Types

> What each scan type checks and which tools it runs.

## `webapp` — Web Application Scan

Tools and what they check:

| Tool | What it checks |
| - | - |
| **nuclei** | Known vulnerabilities (CVE-based templates, critical/ high/ medium severity) |
| **nikto** | Web server misconfigurations, outdated software, dangerous files |
| **whatweb** | Technology fingerprint (CMS, web server, frameworks, analytics) |
| **dirsearch** | Hidden paths, backup files, exposed directories |
| **sqlmap** | SQL injection detection (light level) |

Best for: auditing your own web applications, checking for OWASP Top 10 issues.

***

## `dns-auth` — DNS Authentication Scan

Tools and what they check:

| Tool | What it checks |
| - | - |
| **dig** | A, AAAA, NS, MX and TXT records, and the DMARC record at `_dmarc.<domain>` |
| **curl** | HTTP response headers |

The summary states whether the domain has MX records, an SPF record and a DMARC record, for example `SPF: missing`. DKIM is not checked: its record name depends on a selector only the mail sender knows.

***

## `ip` — Network Scan

Tools and what they check:

| Tool | What it checks |
| - | - |
| **nmap** | Every TCP port, with service and OS detection on the open ones |

Takes about two minutes. The summary lists the open ports with their services, for example `Open ports (3): 53/tcp domain; 80/tcp http; 443/tcp ssl/http`.

Best for: discovering exposed services and unauthorized open ports.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.