Email authentication
SPF and DMARC presence, policy strength, and visible configuration.
FREE PUBLIC DOMAIN SCORE
Run a bounded, credential-free public score against a prospect's domain. See the evidence that was read, the findings it supports, and the checks that remained unread.
Run the free scoreReview a prospect or client domain for public-facing email, DNS, certificate, web, and security-contact evidence. Every pass, gap, unread source, and scoring boundary stays visible. The on-screen result and its PDF are free with no email gate.
A useful first look for the conversation ahead—not a claim about controls hidden inside the business.
SPF and DMARC presence, policy strength, and visible configuration.
DNSKEY and DS reads to determine whether the DNSSEC chain is published.
CAA records that name which certificate authorities may issue.
Authoritative nameserver delegation and observable redundancy.
One bounded HTTPS homepage read for supported security headers.
The RFC 9116 /.well-known/security.txt contact path.
The current domain-security workflow schedules 35 collectors and can produce 123 distinct finding types. A collector can execute multiple atomic checks and return evidence, no finding, an unavailable source, or an error; SCOUTz records that distinction instead of turning missing coverage into a pass.
DNS depth, certificate health, SPF, DMARC, DKIM signals, MTA-STS, TLS-RPT, DNSSEC, CAA, delegation, reputation, and IPv6 mail-path context.
Subdomains, takeover signals, TLS posture, response headers, website compliance, CMS and technology fingerprints, and public-facing hardening context.
Lookalike domains, impersonation signals, source-labeled historical breach associations, outside-in perimeter context, and supported public-exposure evidence.
Public Microsoft 365 tenant discovery, managed-versus-federated identity signals, and the evidence boundary for requesting a customer-approved cloud review.
Hosting, email-security, SaaS, telecom/UC, platform, vendor, and incumbent-management signals derived from public records and fingerprints.
Firmographic, entity, mobile-app, digital-presence, compliance-readiness, and public AI-governance signals that help an MSP prepare the right conversation.
This score reads published DNS, email-authentication, certificate, HTTPS, and related public evidence. It does not enter a tenant, install an agent, test credentials, or turn an unread check into a clean result.
SCOUTz OPEN BETA
Join Open Beta with a real MSP workflow. A person reviews every application before a workspace goes live. SCOUTz runs without an agent or install and never changes a configuration on its own.
SCOUTz prepares the conversation. The relationship and the sale stay yours.