How to read a bug bounty program's scope so you test the right assets — in-scope vs out-of-scope, accepted vulnerability types, and the rules that keep your testing authorized.
Scope is the single most important part of any bug bounty program, because it is what makes your testing authorized. A finding on an out-of-scope asset is not a valid submission — and testing it may not be legal. Reading scope carefully is the first skill a hunter develops.
Programs list the domains, applications, and sometimes IP ranges you may test, and usually an explicit out-of-scope list. Third-party services the organization uses are almost always out of scope even when they are reachable. When in doubt, treat it as out of scope.
Most programs specify which issues they reward and which they consider out of scope (for example, self-XSS or missing best-practice headers with no demonstrated impact). Reporting an explicitly excluded issue wastes everyone's time.