See what the internet
already knows about your domain.
An instant, passive exposure check. Enter a domain and get its DNS and hosting footprint, TLS certificate health, security headers, email spoofing protection and the subdomains sitting in public certificate logs β scored, with the specific things to fix.
Passive checks only, against public records. No account needed, nothing is sent to the target that a normal browser would not send.
Six checks, all from public records.
Nothing here touches your systems in a way an ordinary browser would not. That is the point: it is safe to run against any domain, including one you are about to have a conversation about.
Which addresses answer for the name, who runs the nameservers, and where mail is routed. The starting map of what is exposed and who controls it.
Issuer, expiry date and negotiated protocol version. Expired certificates and deprecated protocol versions are among the most common findings in any external assessment.
HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy β the browser-side controls that are free to set and frequently unset.
SPF and DMARC, including whether the DMARC policy actually rejects anything or is sitting on p=none and only watching.
How many hostnames under your domain have appeared in public certificate transparency logs. Often the first time an organisation learns how large its own surface is.
A single number derived from the deductions above, with every deduction itemised. No black box, and no severity inflation.
The half that costs money to answer.
Public records tell you how a domain is configured. They do not tell you which services are listening, which of those carry known vulnerabilities, or whose credentials for your domain are already circulating. Those answers come from commercial intelligence sources that charge per lookup.
We are explicit about this rather than pretending the free tier is the whole picture. Running paid lookups for anonymous traffic is how free tools get abused until they are withdrawn. An account makes each lookup attributable and rate-limited β and it is free.
Create a free accountWhat people ask before running it.
Is this free attack surface check really free?
Is it legal to scan a domain I do not own?
What does the score actually measure?
Why can it not see my open ports and CVEs for free?
Do you store the results?
Can I use this to show a prospect their exposure?
Configuration is the easy half. The rest needs a test.
An exposure check tells you what is visible. A penetration test tells you what can be done with it. See how the engine behind this tool runs a full assessment.
