External attack surface assessment

See your public exposure before attackers do.

Map internet-facing assets and assess email security, DNS integrity, exposed services, reputation, TLS and HTTP controls. Get a defensible score, prioritized findings and concrete remediation guidance.

  • No account required
  • Bounded, non-intrusive checks
  • Public signals only

Free external assessment

Scan your domain

Live

Enter a bare domain such as example.com. No URL, path or port.

Email DNS Assets Services TLS HTTP

Assessment coverage

SPF, DKIM & DMARC DNSSEC & CAA Subdomains & public IPs Ports & exposed services Reputation & blocklists TLS protocols & ciphers

From discovery to remediation

Understand your internet-facing attack surface in three steps.

  1. 01

    Enter a domain

    No credentials, agent or access to internal systems is required.

  2. 02

    Discover and assess

    SecuTest inventories bounded public assets, then evaluates their exposed security controls.

  3. 03

    Prioritize remediation

    Use the score, technical evidence and implementation guides to address demonstrated weaknesses first.

External security coverage

One assessment across identity, infrastructure and exposure.

SecuTest combines asset inventory with configuration analysis. Inventory findings describe what is public; security findings identify demonstrated weaknesses.

DNS & domain integrity

Validate the public control plane.

Inspect authoritative DNS and signals that affect certificate issuance and record integrity.

  • A, AAAA, NS, CNAME, MX and TXT records
  • DNSSEC validation and CAA policy
  • Dangling records and takeover indicators

Asset inventory

Map the public footprint linked to the domain.

Build a bounded inventory before evaluating the services exposed by those assets.

  • Subdomain discovery
  • Public IPv4 and IPv6 observations
  • Shared and external target context

Exposed services

Identify reachable ports and sensitive services.

Use bounded TCP connections and lightweight fingerprinting without exploitation.

  • Selected public TCP ports
  • Service and banner metadata
  • Sensitive administrative and database exposure

Reputation & blocklists

Check point-in-time domain and IP reputation.

Separate confirmed listings from provider errors, resolver restrictions and unknown results.

  • Domain reputation observations
  • Public IPv4 blocklist observations
  • Explicit provider and coverage limitations

TLS security

Inspect certificates, protocols and cipher suites.

Perform normal, SNI-enabled handshakes to observe the cryptographic configuration actually accepted.

  • Certificate validity and key metadata
  • TLS 1.0 through TLS 1.3 negotiation
  • Weak and legacy cipher-suite detection

HTTP security

Identify missing browser protections.

Inspect response headers that reduce common browser-side attack paths and unnecessary disclosure.

  • HSTS and Content Security Policy
  • Clickjacking and MIME protections
  • Referrer, permissions and server disclosure

From visibility to action

A prioritized external security report, not a raw scanner dump.

The free scan shows the score, risk level and top findings. The full HTML and PDF report unlocks the complete asset inventory, technical evidence, coverage limits, business impact and remediation plan.

SecuTestExternal assessment
HTML + PDF

Security report / example.com

External attack surface assessment

example.com

62/100 High risk
Business impact

Demonstrated weaknesses may increase exposure to impersonation, insecure services, weak transport security and brand abuse.

High Exposed services

Sensitive remote-access service is publicly reachable

A bounded connection confirmed that a sensitive service is exposed on a public IP.

Technical evidence 203.0.113.10:3389 / reachable
Recommended remediation

Restrict the service behind a VPN or an explicit source allowlist.

Open remediation guide
01

Complete inventory

Review discovered subdomains, public IPs, ports and service observations.

02

Defensible scoring

See which demonstrated findings reduced the score and which observations remained informational.

03

Implementation guidance

Use evidence, verification commands and public security guides to remediate each weakness.

Public exposure. Business consequences.

Attack surface gaps rarely remain purely technical.

Weak external controls can affect employees, customers, suppliers, availability and the credibility of your brand.

01

Domain impersonation

Weak email authentication can make fraudulent messages appear legitimate.

02

Unmanaged exposure

Forgotten subdomains, public IPs and reachable services can expand the attack surface.

03

Insecure communications

Obsolete TLS protocols and weak cipher suites reduce transport protection.

04

Reputation damage

Blocklist entries and visible security failures can affect delivery and customer trust.

Simple, transparent pricing

Start free. Pay once for the complete assessment.

No subscription is required for a complete domain security report.

Free scan

€0
Instant risk preview
  • External security score
  • Overall risk level
  • Top priority findings
  • No account required
Run free scan

Full security report

€49one-time
Inventory, evidence and action plan
  • Every detailed security finding
  • Subdomain, IP and service inventory
  • Technical evidence and coverage limits
  • Business impact analysis
  • Prioritized remediation guidance
  • HTML and PDF report downloads
Scan and unlock report

Secure one-time checkout processed by Stripe.

Safe by design

Useful external visibility without intrusive testing.

Bounded checks

Strict query, connection, timeout and handshake budgets constrain every assessment.

No exploitation

The platform does not brute-force credentials, exploit vulnerabilities or send malformed attack payloads.

Protected purchase flow

Report checkout is handled by Stripe and paid downloads require valid access.

Frequently asked questions

Clear scope. No inflated claims.

Is SecuTest an External Attack Surface Management platform?

SecuTest performs automated external attack surface discovery and security assessment. The current one-shot product is not continuous EASM monitoring; recurring monitoring and change detection belong to the future subscription product.

Does SecuTest attempt to hack the target?

No. It uses bounded DNS queries, normal TCP connections, standard TLS handshakes and public HTTP responses. It does not exploit vulnerabilities or gain unauthorized access.

Is this a penetration test?

No. It is an automated external security posture assessment. It identifies common public exposure and configuration weaknesses but does not replace a scoped penetration test.

What does the free scan include?

The free result includes the external security score, risk level and a preview of the most important demonstrated findings. Detailed evidence and inventories remain locked.

What is included in the €49 report?

The full report contains all available findings, asset and service inventories, technical evidence, coverage limitations, business impact, remediation guidance, and downloadable HTML and PDF versions.

What security areas are currently assessed?

Current coverage includes MX, SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI, DNS records, DNSSEC, CAA, dangling records, takeover indicators, subdomains, public IPs, selected TCP services, domain and IP reputation, TLS protocols, cipher suites, certificates and HTTP security headers.

Know what is public

Map your external exposure and prioritize the risks that matter.

Start with a free domain assessment. No account, agent or internal access required.

Run free scan Browse security guides