When you need it
Your domains sit with several registrars and DNS providers, some bought years ago by people who have since left. Records still point at cloud resources that no longer exist, nobody knows which domains send email, and you hear about expiring domains or exposed services from someone else first.
What sets the quote
- Up to 50 DNS zones on up to 2 DNS providers (such as Route 53, Azure DNS, Cloud DNS or Cloudflare) and up to 2 registrars.
- Dangling records are matched against an inventory export you run in AWS Resource Explorer, Azure Resource Graph or Google Cloud Asset Inventory, so the number of accounts, subscriptions or projects does not change the size.
- Up to 100 internet-facing hosts, checked for exposed services and TLS configuration, non-intrusively and only with your written permission.
- Larger estates are quoted after sizing.
What changes
- You know which domains could lapse, be transferred away or be taken over through a dangling record, and what closes each gap.
- You know which of your domains can be spoofed in email, and which DNS records fix it.
- Exposed services and weak TLS on your internet-facing hosts are listed with evidence and ordered by risk.
What you get
- Domain register with the registrar, expiry, auto-renew, transfer lock and account MFA for every domain
- DNS findings on DNSSEC and delegation, CAA records, wildcards and parked domains
- Dangling record list with the subdomain takeover risk of each record, including subdomains found in Certificate Transparency logs
- Email authentication status per domain, covering SPF and its lookup limit, DKIM, DMARC, MTA-STS and TLS-RPT
- External exposure list with the open services and TLS configuration of each internet-facing host
- Findings report with severity, evidence and the fix, plus all findings as a CSV file
- A 60-minute readout with your team
This check is not a penetration test. Scans stay non-intrusive, run only inside the window you approve and cover only the hosts in your written permission. Findings usually lead to DNS as code or email domain protection.
Not included
- Penetration testing. Nothing is exploited and no passwords are tried; we can refer you to a certified partner.
- Fixing the findings (quoted separately, often as DNS as code or email domain protection)
- Hosts and services outside your written permission, and third-party platforms you do not control
- Ongoing monitoring, including alerts on lookalike domains registered by others
What we need from you
- Read-only DNS access: AmazonRoute53ReadOnlyAccess in AWS, Reader on the DNS zones in Azure, DNS Reader in Google Cloud, or a Cloudflare API token with Zone Read and DNS Read.
- Read access to the registrar accounts, or exports of each domain's status and security settings.
- The inventory export, listing public IP addresses, load balancers, storage and CDN endpoints.
- Written permission for the external scans, naming the domains, IP ranges and time window.
How it works
Free 30-minute call, then a written fixed quote and your written permission for the external scans.
Read-only review of registrars, zones and email records, with dangling records matched against your inventory export.
Non-intrusive scans of the permitted hosts, inside the agreed time window.
Report and a 60-minute readout.
At a glance
- Duration
- 1 week
- Price
- Fixed quote after a free 30-minute call
- Delivered by
- Our lead architect
Related services
PKI review
A one-week review of your PKI and certificates, covering the CA hierarchy, certificate inventory, TLS settings and revocation, rated red, amber or green, with an expiry risk list and a roadmap.
Microsoft 365 security baseline
Conditional Access, phishing-resistant MFA and just-in-time admin rights for Microsoft 365, plus Intune policies, Defender for Endpoint and disk encryption for Windows and macOS, designed and rolled out in 1–3 weeks.
Identity modernisation
Business applications moved from passwords and legacy federation to Entra ID single sign-on, with hybrid sync, tenant and domain moves, and one corporate sign-in for AWS and Google Cloud where you need it.