Email security
MX, SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI and related mail-security signals.
External security assessment
SecuTest turns externally observable security signals into prioritized findings, technical evidence and actionable remediation guidance.
How SecuTest works
SecuTest brings fragmented external signals into one bounded workflow, then structures the result so the next action is clear.
Start with a domain or public hostname.
Observe public security controls and reachable exposure.
Prioritize meaningful weaknesses instead of dumping raw signals.
Connect findings to evidence, impact and remediation guidance.
Assessment surface
Coverage depends on the signals available for the submitted target at assessment time. SecuTest separates security findings from inventory observations, unavailable providers and explicit coverage limits.
MX, SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI and related mail-security signals.
DNS records, DNSSEC, CAA, dangling records and takeover indicators where applicable.
Certificates, protocol support and cipher-suite observations from standard TLS handshakes.
Browser-facing HTTP security controls and configuration signals exposed by public responses.
Subdomains, public IP observations, selected reachable TCP services and lightweight metadata.
Point-in-time public domain, IP and blocklist signals with provider errors kept distinct.
From signal to decision
A useful assessment should explain what was observed, why it matters and what can be done next. SecuTest connects findings to technical evidence and remediation context.
The published policy is monitoring-only, which limits enforcement against unauthorized use of the domain in email.
v=DMARC1; p=none; rua=mailto:dmarc@example.com
A monitoring-only policy does not instruct receiving systems to quarantine or reject failing messages.
Review legitimate mail sources and move toward an enforcing policy when operationally safe.
Illustrative example only. Results depend on the assessed target and point-in-time observations.
Product philosophy
Security tooling becomes less useful when every observation is presented with the same weight. SecuTest is designed to make automated external findings easier to understand, defend and act on.
Prioritize meaningful findings instead of turning the report into an undifferentiated scanner dump.
Keep technical observations and explicit context behind the score so results can be reviewed and defended.
Connect weaknesses with remediation guidance and verification context instead of stopping at identification.
Built for different workflows
SecuTest is designed for organizations that need a fast external view and for security providers that need a repeatable assessment workflow.
Explore Partner ReportsUnderstand externally visible weaknesses around a public domain without deploying an agent.
Get a structured starting point for prioritization, remediation and verification.
Support external assessments with clear findings, technical evidence and downloadable reports.
Run authorized assessments in bulk and deliver white-label HTML and PDF reports under your own identity.
Bounded by design
SecuTest assesses externally observable information using bounded DNS queries, normal TCP connections, standard TLS handshakes and public HTTP responses.
Start with a domain
Run the same bounded assessment described on this page, or use SecuTest as a repeatable white-label workflow for authorized client assessments.