Domain Exposure Check
See what your domain exposes to attackers — email spoofing gaps, forgotten subdomains, open services and look-alike domains. Graded A–F in seconds.
What attackers see first
An attacker doesn't start with your firewall — they start with what's already public. Certificate-transparency logs list hosts you may have forgotten. Missing SPF or DMARC records let anyone send email that appears to come from your domain. A registered look-alike domain is usually the first step in a phishing campaign against your staff or customers. All of it is discoverable without touching your systems, which is exactly why it's worth checking yourself first.
Frequently asked questions
What is an external attack surface?
Everything about your organisation that is reachable or discoverable from the public internet without any credentials: your domains and subdomains, the services listening on them, your email authentication records, and look-alike domains someone may have registered to impersonate you.
How does this domain exposure check work?
It queries only free, public sources — DNS over HTTPS for your records and email hygiene (SPF, DMARC, MX), public certificate-transparency logs for subdomains you may have forgotten, Shodan's free InternetDB for open ports and known CVEs on the apex IP, and typosquat resolution checks for impersonation risk.
Is it safe and legal to scan my domain here?
Yes. The check is entirely passive — it reads public records and public log data. Nothing is probed, exploited or logged into. You should still only run checks on domains you own or are authorised to assess.
What does the A–F grade mean?
The score runs 0–100 where higher means more exposed, and maps to a letter grade. Each category contributes risk points with concrete findings, so you can see exactly what drove the grade rather than getting an unexplained number.
Why do forgotten subdomains matter?
Old staging, admin and test hosts are frequently left running unpatched and unmonitored long after anyone remembers them. Certificate-transparency logs reveal hosts that DNS brute-forcing and search engines never surface, which is why they are a common initial access route.
Also free: screen a crypto wallet against OFAC sanctions.
Wallet risk check