External attack surface
See your company the way an attacker does.
Enter a domain. In about ten seconds we’ll map what’s publicly visible — nothing to install, nothing to authorize.
No agents · No credentials · Nothing to install
Scan domains you own or administer. By running a scan you accept our Terms and Privacy Policy.
The scan reads published records only — mail authentication (SPF, DKIM, DMARC), MTA-STS, domain registration and transfer locks, DNSSEC and CAA, certificate transparency logs, publicly indexed hosts and ports, and files like security.txt. No port scanning, no sign-in attempts, nothing private.
This is the outside view only. Most of what goes wrong in a small business is inside Microsoft 365 — MFA gaps, forgotten admins, guest access, Conditional Access. The full scan connects read-only in about five minutes and runs 100+ checks across Microsoft 365 and Azure.