DontBreak

DontBreak's Test Traffic

DontBreak tests a site by opening it in a real browser and working through the steps of a test. This page explains what that traffic looks like. It's written for two groups: customers whose firewall or bot protection is blocking their runs, and site owners who see DontBreak in their logs and want to know what it is.

What a run looks like

  • Where it comes from: Amazon Web Services, region us-east-1 (N. Virginia, USA). Each run starts in a fresh, short-lived container with its own public IP address, so the address changes from run to run. There is no fixed list of IP addresses to allow-list. AWS's published ranges for us-east-1 are shared by every AWS customer there, so allowing them would let in far more than DontBreak.
  • What it identifies as: a regular Chrome or Firefox browser with that browser's standard user agent: a desktop user agent for desktop screen sizes, and a mobile one for mobile sizes. It loads pages, scripts, styles and images, runs JavaScript and accepts cookies, like any visitor. The user agent doesn't mention DontBreak.
  • How much: one browser session for each browser and screen size the test is set to use, going through the test's steps in order. Every run starts clean, with no cookies or storage from earlier runs.
  • When: only when a customer has scheduled it (anywhere from every 15 minutes to once a month), starts it by hand, or starts it from their CI pipeline after a deploy. A run doesn't crawl your site or follow links on its own. It visits the pages the test's steps lead to.

Two other things also load sites from AWS us-east-1: the DontBreak editor, which shows the site in a browser while someone builds or edits a test, and some early-access AI features, which can fetch a few pages of the same site to suggest tests.

Let DontBreak runs through your firewall

Because the IP addresses change, don't allow-list by address, and don't allow-list by user agent either: it's a normal browser user agent, so allowing it would let everyone through. Use a secret request header instead.

Add a custom request header to the test

Open the test's settings, go to Authentication, turn on Custom Request Headers, and add a header with a long random value, for example X-DontBreak-Bypass. To cover every test in a suite, set the header in the suite's settings instead. See Test Suites.

Add a matching rule to your WAF or bot protection

Skip challenges for, or allow, requests that carry that header with that value. Step-by-step rules for Cloudflare and AWS WAF are in Testing Behind Bot Protection.

What to know about the header:

  • It's sent only on requests to your site's own domain and its subdomains (for example shop.example.com and api.example.com when the test starts on www.example.com). Third-party services the page loads, such as a payment provider, a CDN on another domain or an analytics script, never see it.
  • Test runs send it on every browser and screen size, and the editor uses it too while you build the test.
  • The value is stored encrypted and isn't shown again after you save. Leaving it blank on a later edit keeps the stored value.

Treat the header value like a password

Anyone who knows it can get past your bot protection. Use a long random value, keep it out of tickets and chat, and replace it if it leaks: saving a new value in the test or suite settings replaces the old one.

Seeing DontBreak traffic you didn't ask for?

DontBreak runs only go to addresses a customer has entered, and customers agree to test only sites they are authorized to test. If you own a site and didn't ask anyone to test it, or you think someone is misusing DontBreak, email abuse@dontbreak.io with:

  • the URL or URLs that were visited
  • the date and time, with the time zone
  • the IP addresses and user agent from your logs, if you have them

If you're not sure the traffic is ours, send the details anyway: we can check whether any DontBreak run visited that URL at that time. Meanwhile, you can block the traffic like any other unwanted visitor.

Quick reference

WhatDetails
SourceAWS us-east-1 (N. Virginia, USA), a different IP address for each run
Fixed IP listNone
BrowserChrome or Firefox with its standard user agent, at desktop and mobile screen sizes
SessionsA fresh browser for each browser and screen size in a run
TimingThe customer's schedule (every 15 minutes to monthly), manual runs, and CI runs after deploys
Allow-listingA custom request header, set in the test's or suite's settings
Report abuseabuse@dontbreak.io

More about how DontBreak handles data: dontbreak.io/security.

Next steps