• $100 – $10,000 per vulnerability
  • Partial safe harbor
  • No collaboration

Program stats

  • Vulnerabilities rewarded 68
  • Validation within 3 days 75% of submissions are accepted or rejected within 3 days
  • Average payout $1,116.66 within the last 3 months

Latest hall of famers

Recently joined this program

326 total


Please note: This program or engagement does not allow disclosure. You may not release information about vulnerabilities found in this program or engagement to the public.

Verisign’s critical yet mostly invisible role – helping to maintain the security, stability and resiliency of the Domain Name System (DNS) and the internet – can sometimes be overshadowed by more visible aspects of the domain name business. The importance of what we do behind the scenes, however, helps the world connect online every day.

Bug Bounty Program Scope:

Below is a list of in-scope and out-of-scope servers and websites, and a list of eligible and ineligible vulnerabilities to help guide your research. If you are unsure whether a service or vulnerability will qualify you for a bounty or not, feel free to ask

Scope and rewards

Program rules

This program follows Bugcrowd’s standard disclosure terms.

For any testing issues (such as broken credentials, inaccessible application, or Bugcrowd Ninja email problems), please submit through the Bugcrowd Support Portal. We will address your issue as soon as possible.

This program does not offer financial or point-based rewards for P5 — Informational findings. Learn more about Bugcrowd’s VRT.