Acceptable Use Policy
Last updated 12 September 2026
ApexDrift only reads public records. It does not connect to, scan, or send any traffic to the infrastructure behind a domain you search, which is why you can search any domain without proving you own it — the same way a search engine or a WHOIS lookup works.
That is a statement about our software, not a blanket permission for what you do next.
Do not use ApexDrift to
- Plan or support unauthorised access to any system. Finding a hostname is legal; probing or logging into it without authorisation generally is not.
- Stalk, harass, dox, or profile a private individual.
- Circumvent the free tier through automation, scripted account creation, or evading usage limits.
- Resell, redistribute, or republish bulk results as a competing dataset or service.
- Break any law that applies to you or to the people whose data appears in results.
If you are testing someone else's systems
Authorisation is your responsibility, not ours. If you are a penetration tester or bug bounty hunter, confirm the target is in scope before you act on anything ApexDrift shows you. Results frequently include hostnames that belong to third parties — shared hosting, CDNs, acquired companies, former employees' side projects — and those are not automatically in scope just because they share a domain suffix.
Rate limits and automation
Scan quotas exist because every search consumes capacity at the upstream data sources we depend on. Do not script around them. If you need higher volume or programmatic access, contact us and we will work something out rather than have you hammer the service.
Enforcement
We may suspend or terminate accounts that breach this policy, and we may report activity to law enforcement where we are legally required to. We will generally warn you first unless the situation makes that inappropriate.
Reporting
To report abuse, or to ask that a domain you control be excluded from the service, email abuse@apexdrift.org.