Free tool
What an attacker seesof your domainwithout forcing anything.
Strictly passive reconnaissance: public DNS and unauthenticated endpoints only. No connection to your servers, no message sent, nothing that shows up in your logs.
No sign-up · Full result on screen · PDF report by email
What the scan looks at
- Hosting, network and name servers
- Mail routing and security gateway
- SPF, DKIM, DMARC — presence, syntax, alignment
- MTA-STS, TLS-RPT, DNSSEC, CAA, BIMI
- Microsoft 365 tenant and authentication mode
About sixty seconds.
The on-screen result stays free and complete, with no address to leave.
Get this report by email
The PDF goes further than the screen: a summary written for your domain, what the findings mean for your business, and where to start.
And what is not public?
This scan only sees the outside. Your tenant configuration — privileged accounts, external sharing, legacy authentication, logging — needs read access and more than three hundred control points.

