Free scan
External attack surface check, one domain
Enter any domain, yours or a supplier's, and see what an attacker sees from the outside: Company Risk Score, subdomains, exposed services, expiring certificates and findings by severity. You may scan a domain you do not own, because collection is passive and touches nothing - which is precisely why it works for third-party risk.
What the scan covers
Domain
Free scanRegistrar and DNS records for the seed domain.
Subdomain discovery
Free scanNames observed in certificate transparency logs.
IP and hosting
Free scanAddresses the domain and its names resolve to.
Certificates
Free scanIssuers, validity windows and imminent expiry.
Email security
Free scanSPF, DMARC and MX configuration.
HTTP hardening
Free scanTransport and response header configuration.
Technology fingerprint
Free scanServer and platform signals disclosed in responses.
Exposure surface
Free scanNon-production and administrative names exposed publicly.
Vulnerability and KEV
Full platformCVE matching and CISA KEV correlation per asset.
Leaked credentials
Full platformBreach and infostealer records tied to the domain.
Supply chain
Full platformVendor and dependency risk across the estate.
Threat graph
Full platformActor, TTP and infrastructure correlation.
Scoring follows the published model on the methodology page. Segments the free scan cannot assess are reported as not assessed, never estimated.
Questions about the scan
What does the free scan check?
It runs the passive modules: DNS and registrar records, subdomain discovery from certificate transparency, resolved IP addresses, TLS certificates and imminent expiry, SPF and DMARC email security, HTTP hardening headers and disclosed technology, and the public exposure of non-production and administrative names.
Is it legal to scan a domain I do not own?
Yes, because nothing is sent to the target beyond one ordinary request to its public homepage. Everything else is read from public sources such as DNS and certificate transparency logs. That is also the point: it is exactly how you assess a supplier who will never give you access to their systems.
Does the scan touch or affect the target system?
No. There is no port scanning, no vulnerability probing, no authentication attempt and no exploitation. Collection is passive and cannot disrupt a production service.
How long does the scan take?
Usually between fifteen and sixty seconds, depending on how many names the domain has in certificate transparency logs.
How is this different from a penetration test?
A penetration test is authorised, intrusive and manual, and it looks for exploitable paths inside a defined scope. This scan is passive and external: it tells you what is visible and misconfigured from the outside, continuously and at scale, which is a different question from whether a specific system can be broken into.
What does the free scan not include?
Continuous monitoring, the supply chain module across vendors, the threat-intelligence graph, leaked credential detail, findings workflow and evidence export for DORA and NIS2 reporting.
Scan terms
- Passive collection only. No intrusive testing, no authentication, no exploitation.
- Results are point-in-time and provided without warranty of completeness or accuracy.
- Three scans per IP address per day. Scan requests are logged, including a hashed IP address, for abuse monitoring.
- An organisation that has been scanned can request removal of its public report from the report page itself.
More on how findings are produced: methodology, attack surface management and third-party risk.