Free tool · No sign-up
See your company the way an attacker does.
Attackers start with what’s public. Enter your domain and we’ll map what’s visible from the outside — in about ten seconds, with nothing to install.
The free scan
The outside view — read from public records.
- Mail authentication — SPF, DKIM, DMARC
- Mail transport security — MTA-STS, TLS reporting
- Domain registration — expiry and transfer lock
- DNS integrity — DNSSEC and CAA
- Internet-facing hosts and publicly indexed ports
- Published files like security.txt
Tenant Strike Pro adds the inside
Read-only connection to Microsoft 365 and Azure — 130+ checks, five minutes to set up.
- Who signs in without MFA, and which admin accounts exist
- What guests and external users can already reach
- What Conditional Access actually does
- Azure misconfigurations — storage, network rules, access keys
- Vulnerability Watch on your internet-facing services
- Scheduled re-scans, drift alerts, and a fix plan
In our experience most of what goes wrong in a small business is on the inside list, not the outside one.
The free scan reads published information only — the same records a browser or mail server looks up in normal operation. No port scanning, no sign-in attempts, and it’s rate-limited per visitor and per domain. Scan domains you own or administer.
It runs without an email address; the first two findings are shown either way and the rest need one. We’ll email a copy when the address is at the domain that was scanned — we don’t send reports about one company to someone at another — and we may follow up about Tenant Strike. Unsubscribe in one click from anything we send.