External attack surface assessment

Understand your exposure before hackers exploit it.

Assess your public-facing security across email, DNS, exposed services, reputation, TLS and HTTP controls. Receive a defensible score, prioritized findings and actionable remediation guidance.

  • No account required
  • Bounded, non-intrusive checks
  • Public signals only

Free external assessment

Scan your domain

Live

Enter a domain or complete HTTP(S) URL. The exact hostname, including www, is audited.

Email security DNS integrity Subdomains & IPs Ports & services Reputation TLS HTTP headers Misconfigurations

Assessment coverage

SPF, DKIM & DMARC DNSSEC & CAA Subdomains & public IPs Ports & exposed services Reputation & blocklists TLS protocols & cipher suites

Simple, transparent pricing

Security assessments for your own domain and your clients.

Run a free external assessment, unlock a complete security report, or use white-label partner packs to assess prospects and clients under your own brand.

Free scan

$0
Instant risk preview
  • External security score
  • Overall risk level
  • Top priority findings
  • No account required
Run free scan

Full security report

$49one-time
Inventory, evidence and action plan
  • Every detailed security finding
  • Subdomain, IP and service inventory
  • Technical evidence and coverage limits
  • Business impact analysis
  • Prioritized remediation guidance
  • HTML and PDF report downloads
Scan and unlock report

Secure one-time B2B checkout processed by Stripe, excluding applicable taxes. Terms apply.

External security coverage

One assessment across identity, infrastructure and exposure.

Inventory findings describe what is public; security findings identify demonstrated weaknesses and separate them from coverage limits or unavailable providers.

DNS & domain integrity

Validate the public control plane.

Inspect authoritative DNS and signals affecting record integrity and certificate issuance.

  • A, AAAA, NS, CNAME, MX and TXT records
  • DNSSEC validation and CAA policy
  • Dangling records and takeover indicators

Asset inventory

Map the footprint linked to the domain.

Build a bounded inventory before assessing the services exposed by those assets.

  • Subdomain discovery
  • Public IPv4 and IPv6 observations
  • Shared and external target context

Exposed services

Identify reachable ports and sensitive services.

Use bounded TCP connections and lightweight fingerprinting without exploitation.

  • Selected public TCP ports
  • Service and banner metadata
  • Administrative and database exposure

Reputation & blocklists

Check point-in-time domain and IP reputation.

Separate confirmed listings from provider errors, resolver restrictions and unknown results.

  • Domain reputation observations
  • Public IPv4 blocklist observations
  • Explicit provider and coverage limitations

TLS & HTTP security

Inspect transport and browser-facing controls.

Observe accepted protocols, cipher suites, certificates and response security headers.

  • TLS protocol and cipher enumeration
  • Certificate validity and key metadata
  • HSTS, CSP and browser protections

From visibility to action

A prioritized external security report, not a raw scanner dump.

The free scan shows the score, risk level and top findings. Detailed evidence and inventories remain locked until you unlock the full HTML and PDF report, which includes the complete asset inventory, technical evidence, coverage limits, business impact and remediation plan.

SecuTestExternal assessment
HTML + PDF

Security report / example.com

External attack surface assessment

example.com

62/100 High risk
Business impact

Demonstrated weaknesses may increase exposure to impersonation, insecure services, weak transport security and brand abuse.

High Exposed services

Sensitive remote-access service is publicly reachable

A bounded connection confirmed that a sensitive service is exposed on a public IP.

Technical evidence 203.0.113.10:3389 / reachable
Recommended remediation

Restrict the service behind a VPN or an explicit source allowlist.

Open remediation guide
01

Complete inventory

Review discovered subdomains, public IPs, ports and service observations.

02

Defensible scoring

See which demonstrated findings reduced the score and which observations remained informational.

03

Implementation guidance

Use evidence, verification commands and public security guides to remediate each weakness.

Public exposure. Business consequences.

Attack surface gaps rarely remain purely technical.

Weak external controls can affect employees, customers, suppliers, availability and brand credibility.

01

Domain impersonation

Weak email authentication can make fraudulent messages appear legitimate.

02

Unmanaged exposure

Forgotten subdomains, public IPs and reachable services can expand the attack surface.

03

Insecure communications

Obsolete TLS protocols and weak cipher suites reduce transport protection.

04

Reputation damage

Blocklist entries and visible security failures can affect delivery and customer trust.

Safe by design

Useful external visibility without intrusive testing.

Bounded checks

Strict query, connection, timeout and handshake budgets constrain every assessment.

No exploitation

The platform does not brute-force credentials, exploit vulnerabilities or send malformed attack payloads.

Protected purchase flows

Direct reports and partner credit packs use dedicated Stripe checkout and validated access controls.

Frequently asked questions

How MSPs turn domains into opportunities.

How can SecuTest help me win more clients?

SecuTest gives you a reason to contact the prospect.

Scan their domain, find real security issues and show them what you found.

You start with evidence instead of a generic sales pitch.

How can I sell more security services to existing clients?

Run an assessment on the client's domain.

SecuTest can uncover issues that lead to remediation work, security projects or managed services.

Instead of telling the client they need more security, you can show them a real problem first.

How can I use SecuTest during a sales call?

Open the assessment and show the findings.

Instead of saying “Your security could be better,” you can say: “We found this on your domain. Here is why it matters. Here is how we can help fix it.”

It makes the conversation concrete.

Do I need an engineer to create every assessment?

No.

Enter the domain and SecuTest runs the checks automatically.

It finds the issues, organizes the evidence and creates a client-ready report. Your technical team can review the findings when needed, but they do not need to build every assessment by hand.

Can SecuTest help me increase revenue from each client?

It can help you find more things worth discussing with the client.

A finding can lead to remediation work, a security project, a managed service or a wider security review.

The goal is simple: turn technical findings into business opportunities.

Can I send the report under my own brand?

Yes.

Add your company name, logo, colors and support details.

SecuTest creates white-label HTML and PDF reports you can deliver as your own service. Your client sees your company.

Can I try SecuTest before buying a partner pack?

Yes.

Run a free assessment on secutest.io and see the score and priority findings before buying anything.

Partner packs unlock the white-label workflow for your own prospects and clients.

What does SecuTest actually check?

SecuTest looks at the parts of a company that are visible from the internet.

It checks email security, DNS security, subdomains, public IPs, open ports and exposed services, domain and IP reputation, TLS and certificates, and HTTP security headers.

The results are turned into clear findings with evidence and remediation guidance.

SecuTest is an automated external attack surface assessment, not a continuous External Attack Surface Management service. The current product is not continuous EASM monitoring. Continuous monitoring is planned as a future subscription product.

Does SecuTest hack the target?

No.

SecuTest uses public information and normal network requests.

It does not exploit vulnerabilities, log into systems or try to gain unauthorized access.

How do partner credits work?

There is no subscription required.

Buy a pack of 5, 10 or 25 white-label report credits and use them when you need them.

Credits do not expire and do not renew automatically.

Know what is public

Map your external exposure and prioritize the risks that matter.

Start with a free assessment, unlock a complete report, or deliver white-label assessments through the partner workspace.