you x you i logo

Letting our audit reach your site

You are probably here because a website audit could not load your pages, and your security settings turned it away. This page explains who we are, exactly what to look for, and how to let us through for as long as the audit takes.

Who we are

We are you x you i. We read a website the way a first-time visitor would and report back on what is confusing, slow, or getting in the way of a sale.

We only ever read a site when someone has asked us to and paid for that report. We read the pages, we do not fill in forms, we do not buy anything, and we do not try to reach anything behind a login. If an audit of your site is running, someone with access to your business asked for it.

Read this before you change anything

The rule below matches a label we attach to our requests. Be aware of what that means: a label is not a secret. Anyone can send the same one. A rule that waves through everything carrying it will also wave through anyone who copies it, which is why we are not going to tell you to leave it switched on.

So keep it narrow and keep it temporary. Add it when an audit is being blocked, restrict it to your own site, and remove the rule once your report has arrived. An audit takes minutes, not days.

We are also building a stronger version of this, one your firewall can verify for itself instead of taking a label at face value. When that is ready, this page will say so and the rule below can go away for good.

What to match on

Every request we make carries these two labels. Match on both together, never on just one.

Header
X-Youxyoui-Audit

Its value is always https://www.youxyoui.io/allowlist, the page you are reading now.

From
audits@youxyoui.io

The standard way of saying who is responsible for a request. That address reaches a person here.

Please do not build a rule around the browser we appear to be using. We look like an ordinary desktop browser, because that is what we are reading your site with, and a rule based on that would let far too much through.

If you use Cloudflare

  1. In the Cloudflare dashboard, choose your site, then Security › WAF › Custom rules.
  2. Create a rule and give it a name you will recognise later.
  3. Set the condition to: field Custom header, name X-Youxyoui-Audit, operator equals, value https://www.youxyoui.io/allowlist.
  4. Set the action to Skip, and tick the checks you want skipped for us. Skipping the managed rules and the bot fight mode is usually enough.
  5. Save, and drag the rule above any rule that is currently blocking us.
  6. Delete the rule when your report is done. Set a reminder if you are likely to forget.

If you are on a plan without custom rules, the same thing can be done from Security › Settings by lowering the security level for the length of the audit, then putting it back.

If you use something else

The instructions differ, the rule does not. Wherever your firewall lets you write a condition, the shape is the same: when the request has a header called X-Youxyoui-Audit, allow it, and take the rule away afterwards.

  • Wordfence (WordPress): Firewall, then Blocking, then add a rule matching that header.
  • Sucuri: Firewall settings, then Access Control, then the allow list.
  • AWS WAF: a web ACL rule with a single-header string match and an Allow action, placed above your blocking rules.
  • Managed hosting such as SiteGround or WP Engine: their support team can add this for you faster than you can find the setting. Send them this page.

If none of this is yours to change

Most people who reach this page do not manage their own firewall, and that is fine. Forward this page to whoever looks after your website, your developer, your agency, or your hosting support. It tells them everything they need, and it is short on purpose.

Or write to us at support@youxyoui.io with your website address, and we will tell you what we saw when we tried to read your site. If the block is something we can work around from our side, we will do that instead and you can leave your settings alone.

Questions about what we store and for how long are answered in our privacy policy.