PuReAIpureAi
Free scan

Free scan

External attack surface check, one domain

Enter any domain, yours or a supplier's, and see what an attacker sees from the outside: Company Risk Score, subdomains, exposed services, expiring certificates and findings by severity. You may scan a domain you do not own, because collection is passive and touches nothing - which is precisely why it works for third-party risk.

What the scan covers

Domain

Free scan

Registrar and DNS records for the seed domain.

Subdomain discovery

Free scan

Names observed in certificate transparency logs.

IP and hosting

Free scan

Addresses the domain and its names resolve to.

Certificates

Free scan

Issuers, validity windows and imminent expiry.

Email security

Free scan

SPF, DMARC and MX configuration.

HTTP hardening

Free scan

Transport and response header configuration.

Technology fingerprint

Free scan

Server and platform signals disclosed in responses.

Exposure surface

Free scan

Non-production and administrative names exposed publicly.

Vulnerability and KEV

Full platform

CVE matching and CISA KEV correlation per asset.

Leaked credentials

Full platform

Breach and infostealer records tied to the domain.

Supply chain

Full platform

Vendor and dependency risk across the estate.

Threat graph

Full platform

Actor, TTP and infrastructure correlation.

Scoring follows the published model on the methodology page. Segments the free scan cannot assess are reported as not assessed, never estimated.

Questions about the scan

What does the free scan check?

It runs the passive modules: DNS and registrar records, subdomain discovery from certificate transparency, resolved IP addresses, TLS certificates and imminent expiry, SPF and DMARC email security, HTTP hardening headers and disclosed technology, and the public exposure of non-production and administrative names.

Is it legal to scan a domain I do not own?

Yes, because nothing is sent to the target beyond one ordinary request to its public homepage. Everything else is read from public sources such as DNS and certificate transparency logs. That is also the point: it is exactly how you assess a supplier who will never give you access to their systems.

Does the scan touch or affect the target system?

No. There is no port scanning, no vulnerability probing, no authentication attempt and no exploitation. Collection is passive and cannot disrupt a production service.

How long does the scan take?

Usually between fifteen and sixty seconds, depending on how many names the domain has in certificate transparency logs.

How is this different from a penetration test?

A penetration test is authorised, intrusive and manual, and it looks for exploitable paths inside a defined scope. This scan is passive and external: it tells you what is visible and misconfigured from the outside, continuously and at scale, which is a different question from whether a specific system can be broken into.

What does the free scan not include?

Continuous monitoring, the supply chain module across vendors, the threat-intelligence graph, leaked credential detail, findings workflow and evidence export for DORA and NIS2 reporting.

Scan terms

More on how findings are produced: methodology, attack surface management and third-party risk.