I am recently facing port scans from ip's of sites I would have just been into. NSLOOKUP tells me that these ip's relate to netsol.com and waldonet.net.mt the latter being the dns server of a local ISP. Are these actually happening or would it have something to do with the actions performed at that site For example at netsol I made a domain name purchase. William