Documentation
Everything written down,
in one place.
How to read a report, what a check sends, how to run your own copy, and how to reach us. Short pages here; the full reasoning lives with the source.
01 / Reading a report
What a result means.
Each check has its own rules and its own limits. These pages explain both.
Transport
The TLS handshake and certificate: what is graded, what is only reported, and what a scan cannot see.
Rule set porch-tls-v7Reach
How a site is reached over HTTP and HTTPS, and exactly what the web check sends to a server.
Rule set porch-web-v3What the domain's DNS says about its mail, what the check connects to, and why an exchanger may not answer.
Rule set porch-mail-v2DNS
How the domain itself is served: its name servers, what it publishes, and whether its DNSSEC chain holds.
Rule set porch-dns-v1What changed
Every rule set version, and what each one grades differently.
On GitHub02 / Privacy & terms
What is kept, and what is agreed.
03 / Run it yourself
Your machine, your scope.
Porch is built to be run by the people responsible for what it checks.
Self-hosting
Docker or a single binary, proof of control for every domain, and a certificate for a public address.
On GitHubVerify a download
Check a release's signature and rebuild it yourself, byte for byte.
On GitHubWho may scan what
The boundaries a copy enforces, and the reasoning behind each one.
On GitHub04 / Security & source
Check it, and tell us.
Report a vulnerability
How to reach us privately, and the fingerprint of the key to encrypt to.
On GitHubGuarantees and their tests
Every promise this project makes, each with the test that fails if it is broken.
On GitHubSource
The whole of it, under the AGPL-3.0, with no third-party dependencies.
On GitHubThe key itself is served at /pgp-key.txt and the contact details at security.txt. Compare the key's fingerprint with the one on GitHub before using it.