Origin Bypass Check
origin_bypass_checkCheck if a WAF-protected host resolves directly to its origin IP. Flags exposed origins that can be bypassed by hitting the real IP with a spoofed Host header.
Instructions
Check whether a WAF-protected host resolves directly to its origin IP.
If the A record lands outside known WAF/CDN ranges, the origin is exposed and the WAF can be bypassed by hitting that IP with a spoofed Host header.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| host | Yes | Hostname, e.g. "example.com". | |
| from_token | No | Optional scan_token from an earlier call. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |