Methods and boundaries
What does Hide’s evidence actually prove?

Ask about a method, source or limitation. Hide distinguishes an observation from a verified outcome and an unknown from a pass.

General information from an AI assistant, not a real check. Private by design, never sold or used for training.

Clear methodology

Clear method changelog

Every Clear report records the method version used at collection time. This page explains material changes to evidence collection, verdict thresholds and safety boundaries.

September 5, 2026

clear-public-v7

  • Added privacy-bounded registrar discovery through the official IANA RDAP bootstrap registry.
  • Distinguished the registrar from the DNS host so DNSSEC instructions can identify both responsible providers.
  • Retained only the registrar identity and discarded registrant contact information returned by RDAP services.

September 5, 2026

clear-public-v6

  • Added public nameserver and service-provider detection for clearer ownership and handoff.
  • Replaced static severity-first presentation with business-context prioritization.
  • Added outcome-based remediation plans, deployment cautions, single-check re-testing and before/after proof.
  • Separated externally observed evidence, owner-confirmed controls and unassessed areas.

September 3, 2026

clear-public-v5

  • Added one source-backed SMTP DANE finding for every published MX host.
  • Require DNSSEC authentication and usable DANE-TA(2) or DANE-EE(3) TLSA parameters for a narrow pass.
  • Treat missing DANE as an observation rather than a failure and distinguish unavailable DNS from insecure records.
  • Kept STARTTLS negotiation and live certificate matching outside the public DNS check.

September 3, 2026

clear-public-v4

  • Added the required MTA-STS HTTPS policy endpoint as a separate source-backed finding.
  • Validated policy syntax, mode, maximum age and exact or one-label wildcard coverage of every published MX host.
  • Separated missing policy hosts, unavailable DNS and unsafe network targets so the report does not overstate evidence.
  • Kept live SMTP STARTTLS and mail-server certificate testing outside the permission-safe public scan.

September 3, 2026

clear-public-v3

  • Added source-backed MTA-STS and SMTP TLS reporting DNS checks.
  • Added explicit null MX handling so domains that declare no mail service do not receive irrelevant transport-policy actions.
  • Documented that Clear does not fetch the MTA-STS HTTPS policy or test live SMTP transport.
  • Expanded the labeled scanner regression set for mail-routing and transport-policy edge cases.

September 3, 2026

clear-public-v2

  • Separated pass, action, observed and unverified verdicts.
  • Added DNSSEC, CAA, HSTS, Content Security Policy and security.txt evidence.
  • Added explicit private-network and redirect safety checks, method versioning and bounded scan limits.
  • Added fix verification with resolved, new and unchanged action counts.

September 3, 2026

clear-public-v1

  • Introduced the free public domain scan and source-backed report format.

How to read the changelog

A newer method can change a verdict even when the underlying public configuration has not changed. Compare reports with the same method version when measuring a fix, and review this record when versions differ.

Read the current methodology