What it is
One fault,
verified twice,
sent once.
The scanner reads publicly available pages and public DNS records, in the same way a search engine does.
Checked by something else entirely
When it finds something serious, a second and completely separate piece of code re-checks the same fact using different tools. Only a fault that both agree on is ever worth anyone's time.
If the two disagree, nothing is sent. If the fault has been fixed since we saw it, nothing is sent.
Not the usual opener
If it turns out to be the kind of thing every certificate vendor already emails about, it is not used as an opener, because you have read that email before.
One business, one email, ever.
There is no sequence, no follow-up, and no second attempt from a different address. That is enforced by a uniqueness constraint in the database rather than by good intentions.
And it visits quietly
You should never notice it was there.
robots.txt
Read on every request. Not cached, not ignored.
One request / 2s
Per site, at most. A full check is a few dozen requests over a couple of minutes.
Named honestly
The User-Agent says leak-scanner and links here.