01 · Operator
Who operates l9scan (LeakIX)
- Company
- LeakIX (BaDaaS SRL)
- Type
- Monitoring bot
- Official docs
- leakix.net
02 · Behavior
What l9scan (LeakIX) does
LeakIX scans the internet, finds services and indexes them. It records common security misconfigurations and data leaks. Critical leaks get a 30-day grace period in which hosts and CERTs are warned. After that, findings become public in the LeakIX index.
03 · Impact
Why l9scan (LeakIX) matters for your site
If you allow it
- Findings may warn you about exposed services
- Hosting companies and CERTs get notified of critical leaks
If you block it
- Probes target configuration files and admin paths
- Findings become public after 30 days
- No search or traffic benefit
04 · Allow
How to allow l9scan (LeakIX)
robots.txt
User-agent: l9scan
Allow: /
Cloudflare
# Security › WAF › Custom rules › Create rule
Expression: (http.user_agent contains "l9scan")
Action: Skip › All Super Bot Fight Mode rules
# Also check Security › Bots: "Block AI bots" can block it regardless of robots.txt.
WordPress
# WordPress serves a virtual robots.txt. Edit it with your SEO plugin:
# Yoast: SEO › Tools › File editor · Rank Math: General Settings › Edit robots.txt
User-agent: l9scan
Allow: /
nginx
# nginx serves every user agent by default.
# Make sure no rule like this blocks it:
# if ($http_user_agent ~* "l9scan") { return 403; }
Apache
# Apache serves every user agent by default.
# Make sure .htaccess has no rule like this:
# RewriteCond %{HTTP_USER_AGENT} l9scan [NC]
# RewriteRule .* - [F,L]
05 · Block
How to block l9scan (LeakIX)
Start with robots.txt. If l9scan (LeakIX) keeps showing up in your logs, block it at your CDN or web server.
robots.txt
User-agent: l9scan
Disallow: /
Cloudflare
# Security › WAF › Custom rules › Create rule
Expression: (http.user_agent contains "l9scan")
Action: Block
WordPress
# WordPress serves a virtual robots.txt. Edit it with your SEO plugin:
# Yoast: SEO › Tools › File editor · Rank Math: General Settings › Edit robots.txt
User-agent: l9scan
Disallow: /
nginx
# In your server { } block:
if ($http_user_agent ~* "l9scan") {
return 403;
}
Apache
# .htaccess
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteCond %{HTTP_USER_AGENT} l9scan [NC]
RewriteRule .* - [F,L]
</IfModule>
06 · User agents
User agents we see for l9scan (LeakIX)
| User agent | Share | Last seen | Status |
|---|---|---|---|
Mozilla/5.0 (l9scan/2.0.933313e2839313e2630313e27383; +https://leakix.net) |
100% | Unverified |
07 · Verification
Is it really l9scan (LeakIX)?
l9scan (LeakIX)’s operator publishes no IP ranges or hostnames, so requests cannot be verified. Treat the user agent as a claim, and watch your logs for unusual request rates.
FAQ
Questions about l9scan (LeakIX)
What is l9scan?
l9scan is the scanner user agent of LeakIX. It probes servers to index exposed services and security misconfigurations.
How do I get my site removed from LeakIX?
LeakIX lists blacklist@leakix.net for take-down and blacklist requests.
Is l9scan malicious?
It is run by a security research project that publishes findings after a 30-day grace period. It still probes for sensitive files, so many sites block it.
Last reviewed Oct 8, 2026