Free tool · No sign-up

See your company the way an attacker does.

Attackers start with what’s public. Enter your domain and we’ll map what’s visible from the outside — in about ten seconds, with nothing to install.

Run a free scan →No agents · No credentials · No account
What you get

The free scan

The outside view — read from public records.

  • Mail authentication — SPF, DKIM, DMARC
  • Mail transport security — MTA-STS, TLS reporting
  • Domain registration — expiry and transfer lock
  • DNS integrity — DNSSEC and CAA
  • Internet-facing hosts and publicly indexed ports
  • Published files like security.txt

Tenant Strike Pro adds the inside

Read-only connection to Microsoft 365 and Azure — 130+ checks, five minutes to set up.

  • Who signs in without MFA, and which admin accounts exist
  • What guests and external users can already reach
  • What Conditional Access actually does
  • Azure misconfigurations — storage, network rules, access keys
  • Vulnerability Watch on your internet-facing services
  • Scheduled re-scans, drift alerts, and a fix plan

In our experience most of what goes wrong in a small business is on the inside list, not the outside one.

The free scan reads published information only — the same records a browser or mail server looks up in normal operation. No port scanning, no sign-in attempts, and it’s rate-limited per visitor and per domain. Scan domains you own or administer.

It runs without an email address; the first two findings are shown either way and the rest need one. We’ll email a copy when the address is at the domain that was scanned — we don’t send reports about one company to someone at another — and we may follow up about Tenant Strike. Unsubscribe in one click from anything we send.