FREE PUBLIC DOMAIN SCORE

See what a prospect's domain can tell you.

Run a bounded, credential-free public score against a prospect's domain. See the evidence that was read, the findings it supports, and the checks that remained unread.

Run the free score
SCOUTz PROSPECT EVIDENCE · ONE DOMAIN

Build the evidence-backed first look.

Review a prospect or client domain for public-facing email, DNS, certificate, web, and security-contact evidence. Every pass, gap, unread source, and scoring boundary stays visible. The on-screen result and its PDF are free with no email gate.

5SCORES / UTC DAY
PER IP OR DEVICE
SEE EXACTLY WHAT THE FREE CHECK REVIEWS

Six practical security areas. Fourteen bounded public reads.

A useful first look for the conversation ahead—not a claim about controls hidden inside the business.

01

Email authentication

SPF and DMARC presence, policy strength, and visible configuration.

02

DNS trust

DNSKEY and DS reads to determine whether the DNSSEC chain is published.

03

Certificate authorization

CAA records that name which certificate authorities may issue.

04

Delegation resilience

Authoritative nameserver delegation and observable redundancy.

05

Web response protections

One bounded HTTPS homepage read for supported security headers.

06

Security contact

The RFC 9116 /.well-known/security.txt contact path.

No email gate. One domain at a time. No bulk scan, login, port sweep, history, monitoring, or claim that an organization is secure.

WHAT THE FULL SCOUTz DOMAIN REVIEW ADDS

The public score is the doorway. The domain engine is the building.

The current domain-security workflow schedules 35 collectors and can produce 123 distinct finding types. A collector can execute multiple atomic checks and return evidence, no finding, an unavailable source, or an error; SCOUTz records that distinction instead of turning missing coverage into a pass.

DNS, certificates, and mail

DNS depth, certificate health, SPF, DMARC, DKIM signals, MTA-STS, TLS-RPT, DNSSEC, CAA, delegation, reputation, and IPv6 mail-path context.

External web surface

Subdomains, takeover signals, TLS posture, response headers, website compliance, CMS and technology fingerprints, and public-facing hardening context.

Brand and exposure

Lookalike domains, impersonation signals, source-labeled historical breach associations, outside-in perimeter context, and supported public-exposure evidence.

Cloud doorstep

Public Microsoft 365 tenant discovery, managed-versus-federated identity signals, and the evidence boundary for requesting a customer-approved cloud review.

Technology and providers

Hosting, email-security, SaaS, telecom/UC, platform, vendor, and incumbent-management signals derived from public records and fingerprints.

Business context

Firmographic, entity, mobile-app, digital-presence, compliance-readiness, and public AI-governance signals that help an MSP prepare the right conversation.

Public evidence has a boundary.

This score reads published DNS, email-authentication, certificate, HTTPS, and related public evidence. It does not enter a tenant, install an agent, test credentials, or turn an unread check into a clean result.

SCOUTz OPEN BETA

Point SCOUTz at your next prospect. Walk in with a defensible answer.

Join Open Beta with a real MSP workflow. A person reviews every application before a workspace goes live. SCOUTz runs without an agent or install and never changes a configuration on its own.

SCOUTz prepares the conversation. The relationship and the sale stay yours.