EU-ACCES scanner
EU-ACCES performs automated technical screening of public webpages. It does not attempt to hide that automation or bypass a site's access controls.
Identification
Public Essential requests use a standards-compatible HTTP user agent that still identifies EU-ACCES, without unsolicited custom scanner headers. Public Deep scans use the remote Chromium browser's ordinary request headers; verified-domain Deep scans additionally include X-EUCheck-Scanner: deep plus the owner's authorization value so the owner can allow them in their own WAF.
Verified-domain allow rule
X-EUCheck-Scanner: essential|deep X-EUCheck-Authorization: <owner-specific token>
Only the verified owner sees that authorization token. EU-ACCES sends it only to the verified hostname, not to third-party resources loaded by the page.
Behaviour
- Public URLs only; private/local networks are blocked.
- Rate limits and upstream 429 responses are respected.
- EU-ACCES does not log into the target site unless a future explicit owner-authorized feature says otherwise.
- A successful scan is technical evidence at a point in time, not a legal certification.
Scanner information URL: https://euacces.com/scanner