00
The scan
Free, passive, no loginEverything an attacker can learn about you before they touch you.
These are the first signals we check on every engagement, before any active testing begins. Each one is passive: the same requests your browser already makes when it visits a site. Nothing is exploited and nothing is logged in to.
Please only scan domains you are authorised to test. Rate limited to five scans per ten minutes.
- DNS and email authenticationSPF, DMARC and the records that decide whether anyone can send mail as you.
- TLS and certificateProtocol versions, expiry, and whether the chain actually validates.
- HTTP security headersWhat the server tells a browser to enforce, and what it leaves open.
- Subdomain exposureCertificate transparency logs, which is where forgotten hosts surface first.
Scan output
–/ 100
Perimeter grade
None of this needed credentials or exploitation to find, which is exactly why it is worth closing before someone else finds it first.
This is the view from outside. An engagement gets you the view from inside, which is where the risk in most environments actually lives.
Book a scoping call