Domain verification
All active probingA DNS TXT record at _secscan-challenge.<domain>, or a file at /.well-known/secscan-verification.txt
Without it only passive checks run. This is the control that stops the platform being used as an anonymous attack proxy, so it fails closed — a lookup error denies rather than allows.