Email security
Reduce spoofing and impersonation risk.
Evaluate mail routing and the controls used to authenticate legitimate senders.
- MX and Null MX configuration
- SPF, DKIM and DMARC analysis
- MTA-STS, TLS-RPT and BIMI signals
External attack surface assessment
Map internet-facing assets and assess email security, DNS integrity, exposed services, reputation, TLS and HTTP controls. Get a defensible score, prioritized findings and concrete remediation guidance.
Free external assessment
Enter a bare domain such as example.com. No URL, path or port.
External posture result
Security score
Your externally visible controls have been assessed.
Unlock every finding, inventory, evidence item and remediation step.
Assessment coverage
From discovery to remediation
No credentials, agent or access to internal systems is required.
SecuTest inventories bounded public assets, then evaluates their exposed security controls.
Use the score, technical evidence and implementation guides to address demonstrated weaknesses first.
External security coverage
SecuTest combines asset inventory with configuration analysis. Inventory findings describe what is public; security findings identify demonstrated weaknesses.
Email security
Evaluate mail routing and the controls used to authenticate legitimate senders.
DNS & domain integrity
Inspect authoritative DNS and signals that affect certificate issuance and record integrity.
Asset inventory
Build a bounded inventory before evaluating the services exposed by those assets.
Exposed services
Use bounded TCP connections and lightweight fingerprinting without exploitation.
Reputation & blocklists
Separate confirmed listings from provider errors, resolver restrictions and unknown results.
TLS security
Perform normal, SNI-enabled handshakes to observe the cryptographic configuration actually accepted.
HTTP security
Inspect response headers that reduce common browser-side attack paths and unnecessary disclosure.
From visibility to action
The free scan shows the score, risk level and top findings. The full HTML and PDF report unlocks the complete asset inventory, technical evidence, coverage limits, business impact and remediation plan.
External attack surface assessment
Demonstrated weaknesses may increase exposure to impersonation, insecure services, weak transport security and brand abuse.
A bounded connection confirmed that a sensitive service is exposed on a public IP.
203.0.113.10:3389 / reachable
Restrict the service behind a VPN or an explicit source allowlist.
Review discovered subdomains, public IPs, ports and service observations.
See which demonstrated findings reduced the score and which observations remained informational.
Use evidence, verification commands and public security guides to remediate each weakness.
Public exposure. Business consequences.
Weak external controls can affect employees, customers, suppliers, availability and the credibility of your brand.
Weak email authentication can make fraudulent messages appear legitimate.
Forgotten subdomains, public IPs and reachable services can expand the attack surface.
Obsolete TLS protocols and weak cipher suites reduce transport protection.
Blocklist entries and visible security failures can affect delivery and customer trust.
Simple, transparent pricing
No subscription is required for a complete domain security report.
Free scan
Full security report
Secure one-time checkout processed by Stripe.
Safe by design
Strict query, connection, timeout and handshake budgets constrain every assessment.
The platform does not brute-force credentials, exploit vulnerabilities or send malformed attack payloads.
Report checkout is handled by Stripe and paid downloads require valid access.
Frequently asked questions
SecuTest performs automated external attack surface discovery and security assessment. The current one-shot product is not continuous EASM monitoring; recurring monitoring and change detection belong to the future subscription product.
No. It uses bounded DNS queries, normal TCP connections, standard TLS handshakes and public HTTP responses. It does not exploit vulnerabilities or gain unauthorized access.
No. It is an automated external security posture assessment. It identifies common public exposure and configuration weaknesses but does not replace a scoped penetration test.
The free result includes the external security score, risk level and a preview of the most important demonstrated findings. Detailed evidence and inventories remain locked.
The full report contains all available findings, asset and service inventories, technical evidence, coverage limitations, business impact, remediation guidance, and downloadable HTML and PDF versions.
Current coverage includes MX, SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI, DNS records, DNSSEC, CAA, dangling records, takeover indicators, subdomains, public IPs, selected TCP services, domain and IP reputation, TLS protocols, cipher suites, certificates and HTTP security headers.
Know what is public
Start with a free domain assessment. No account, agent or internal access required.