Skip to content
All services
Identity, PKI & domainsAssess

Domain and external attack surface check

A one-week, non-intrusive check of your domains, DNS, email authentication and internet-facing endpoints, with every finding tied to evidence and a fix. It is not a penetration test.

When you need it

Your domains sit with several registrars and DNS providers, some bought years ago by people who have since left. Records still point at cloud resources that no longer exist, nobody knows which domains send email, and you hear about expiring domains or exposed services from someone else first.

What sets the quote

  • Up to 50 DNS zones on up to 2 DNS providers (such as Route 53, Azure DNS, Cloud DNS or Cloudflare) and up to 2 registrars.
  • Dangling records are matched against an inventory export you run in AWS Resource Explorer, Azure Resource Graph or Google Cloud Asset Inventory, so the number of accounts, subscriptions or projects does not change the size.
  • Up to 100 internet-facing hosts, checked for exposed services and TLS configuration, non-intrusively and only with your written permission.
  • Larger estates are quoted after sizing.

What changes

  • You know which domains could lapse, be transferred away or be taken over through a dangling record, and what closes each gap.
  • You know which of your domains can be spoofed in email, and which DNS records fix it.
  • Exposed services and weak TLS on your internet-facing hosts are listed with evidence and ordered by risk.

What you get

  • Domain register with the registrar, expiry, auto-renew, transfer lock and account MFA for every domain
  • DNS findings on DNSSEC and delegation, CAA records, wildcards and parked domains
  • Dangling record list with the subdomain takeover risk of each record, including subdomains found in Certificate Transparency logs
  • Email authentication status per domain, covering SPF and its lookup limit, DKIM, DMARC, MTA-STS and TLS-RPT
  • External exposure list with the open services and TLS configuration of each internet-facing host
  • Findings report with severity, evidence and the fix, plus all findings as a CSV file
  • A 60-minute readout with your team

This check is not a penetration test. Scans stay non-intrusive, run only inside the window you approve and cover only the hosts in your written permission. Findings usually lead to DNS as code or email domain protection.

Not included

  • Penetration testing. Nothing is exploited and no passwords are tried; we can refer you to a certified partner.
  • Fixing the findings (quoted separately, often as DNS as code or email domain protection)
  • Hosts and services outside your written permission, and third-party platforms you do not control
  • Ongoing monitoring, including alerts on lookalike domains registered by others

What we need from you

  • Read-only DNS access: AmazonRoute53ReadOnlyAccess in AWS, Reader on the DNS zones in Azure, DNS Reader in Google Cloud, or a Cloudflare API token with Zone Read and DNS Read.
  • Read access to the registrar accounts, or exports of each domain's status and security settings.
  • The inventory export, listing public IP addresses, load balancers, storage and CDN endpoints.
  • Written permission for the external scans, naming the domains, IP ranges and time window.

How it works

  1. Free 30-minute call, then a written fixed quote and your written permission for the external scans.

  2. Read-only review of registrars, zones and email records, with dangling records matched against your inventory export.

  3. Non-intrusive scans of the permitted hosts, inside the agreed time window.

  4. Report and a 60-minute readout.

At a glance

Duration
1 week
Price
Fixed quote after a free 30-minute call
Delivered by
Our lead architect
Assess

PKI review

A one-week review of your PKI and certificates, covering the CA hierarchy, certificate inventory, TLS settings and revocation, rated red, amber or green, with an expiry risk list and a roadmap.

Duration:1 week
Build Popular

Microsoft 365 security baseline

Conditional Access, phishing-resistant MFA and just-in-time admin rights for Microsoft 365, plus Intune policies, Defender for Endpoint and disk encryption for Windows and macOS, designed and rolled out in 1–3 weeks.

Duration:1–3 weeks
Build

Identity modernisation

Business applications moved from passwords and legacy federation to Entra ID single sign-on, with hybrid sync, tenant and domain moves, and one corporate sign-in for AWS and Google Cloud where you need it.

Duration:2–6 weeks

Not sure where to start?

Book a free 30-minute call. We learn what you need and tell you honestly whether and how we can help. There is no obligation.