External attack surface assessment

Understand your exposure before hackers exploit it.

Assess your public-facing security across email, DNS, exposed services, reputation, TLS and HTTP controls. Receive a defensible score, prioritized findings and actionable remediation guidance.

  • No account required
  • Bounded, non-intrusive checks
  • Public signals only

Free external assessment

Scan your domain

Live

Enter a domain or complete HTTP(S) URL. The exact hostname, including www, is audited.

Email security DNS integrity Subdomains & IPs Ports & services Reputation TLS HTTP headers Misconfigurations

Assessment coverage

SPF, DKIM & DMARC DNSSEC & CAA Subdomains & public IPs Ports & exposed services Reputation & blocklists TLS protocols & cipher suites

External security coverage

One assessment across identity, infrastructure and exposure.

Inventory findings describe what is public; security findings identify demonstrated weaknesses and separate them from coverage limits or unavailable providers.

DNS & domain integrity

Validate the public control plane.

Inspect authoritative DNS and signals affecting record integrity and certificate issuance.

  • A, AAAA, NS, CNAME, MX and TXT records
  • DNSSEC validation and CAA policy
  • Dangling records and takeover indicators

Asset inventory

Map the footprint linked to the domain.

Build a bounded inventory before assessing the services exposed by those assets.

  • Subdomain discovery
  • Public IPv4 and IPv6 observations
  • Shared and external target context

Exposed services

Identify reachable ports and sensitive services.

Use bounded TCP connections and lightweight fingerprinting without exploitation.

  • Selected public TCP ports
  • Service and banner metadata
  • Administrative and database exposure

Reputation & blocklists

Check point-in-time domain and IP reputation.

Separate confirmed listings from provider errors, resolver restrictions and unknown results.

  • Domain reputation observations
  • Public IPv4 blocklist observations
  • Explicit provider and coverage limitations

TLS & HTTP security

Inspect transport and browser-facing controls.

Observe accepted protocols, cipher suites, certificates and response security headers.

  • TLS protocol and cipher enumeration
  • Certificate validity and key metadata
  • HSTS, CSP and browser protections

Simple, transparent pricing

Use SecuTest directly or deliver reports under your own brand.

Direct reports are purchased per domain. Partner packs give agencies, MSPs and consultants access to white-label reporting and Bulk Domain Scan for up to 100 domains per job.

Free scan

$0
Instant risk preview
  • External security score
  • Overall risk level
  • Top priority findings
  • No account required
Run free scan

Full security report

$49one-time
Inventory, evidence and action plan
  • Every detailed security finding
  • Subdomain, IP and service inventory
  • Technical evidence and coverage limits
  • Business impact analysis
  • Prioritized remediation guidance
  • HTML and PDF report downloads
Scan and unlock report

Secure one-time B2B checkout processed by Stripe, excluding applicable taxes. Terms apply.

From visibility to action

A prioritized external security report, not a raw scanner dump.

The free scan shows the score, risk level and top findings. Detailed evidence and inventories remain locked until you unlock the full HTML and PDF report, which includes the complete asset inventory, technical evidence, coverage limits, business impact and remediation plan.

SecuTestExternal assessment
HTML + PDF

Security report / example.com

External attack surface assessment

example.com

62/100 High risk
Business impact

Demonstrated weaknesses may increase exposure to impersonation, insecure services, weak transport security and brand abuse.

High Exposed services

Sensitive remote-access service is publicly reachable

A bounded connection confirmed that a sensitive service is exposed on a public IP.

Technical evidence 203.0.113.10:3389 / reachable
Recommended remediation

Restrict the service behind a VPN or an explicit source allowlist.

Open remediation guide
01

Complete inventory

Review discovered subdomains, public IPs, ports and service observations.

02

Defensible scoring

See which demonstrated findings reduced the score and which observations remained informational.

03

Implementation guidance

Use evidence, verification commands and public security guides to remediate each weakness.

Public exposure. Business consequences.

Attack surface gaps rarely remain purely technical.

Weak external controls can affect employees, customers, suppliers, availability and brand credibility.

01

Domain impersonation

Weak email authentication can make fraudulent messages appear legitimate.

02

Unmanaged exposure

Forgotten subdomains, public IPs and reachable services can expand the attack surface.

03

Insecure communications

Obsolete TLS protocols and weak cipher suites reduce transport protection.

04

Reputation damage

Blocklist entries and visible security failures can affect delivery and customer trust.

Safe by design

Useful external visibility without intrusive testing.

Bounded checks

Strict query, connection, timeout and handshake budgets constrain every assessment.

No exploitation

The platform does not brute-force credentials, exploit vulnerabilities or send malformed attack payloads.

Protected purchase flows

Direct reports and partner credit packs use dedicated Stripe checkout and validated access controls.

Frequently asked questions

Clear scope. No inflated claims.

Is SecuTest an External Attack Surface Management platform?

SecuTest performs automated external attack surface discovery and security assessment. The current one-shot product is not continuous EASM monitoring. Continuous monitoring is planned as a future subscription product.

Does SecuTest attempt to hack the target?

No. It uses bounded DNS queries, normal TCP connections, standard TLS handshakes and public HTTP responses. It does not exploit vulnerabilities or gain unauthorized access.

What is included in the $49 report?

The full report contains all available findings, asset and service inventories, technical evidence, coverage limitations, business impact, remediation guidance, and downloadable HTML and PDF versions.

How do white-label partner reports work?

Buy a pack without creating an account first. After payment, verify your email, create a password, configure your branding and deliver client-ready HTML and PDF reports without SecuTest attribution.

Can white-label credits be purchased without a subscription?

Yes. The partner workspace offers one-time packs of 5, 10 or 25 report credits. Purchased credits do not expire and do not renew automatically.

What is included in guided remediation?

Guided remediation covers one domain and one report, personalized implementation assistance for the agreed fixes, and one verification scan. It starts from $399.

What security areas are currently assessed?

Current coverage includes MX, SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI, DNS records, DNSSEC, CAA, dangling records, takeover indicators, subdomains, public IPs, selected TCP services, reputation, TLS protocols, cipher suites, certificates and HTTP security headers.

Know what is public

Map your external exposure and prioritize the risks that matter.

Start with a free assessment, unlock a complete report, or deliver white-label assessments through the partner workspace.