MSP owner and business owner reviewing a public-source evidence packet
MSP owner and business owner reviewing a public-source evidence packet

There is no universal yes or no: an MSP's permissionless domain review must be assessed by its collection method, authorization and applicable federal and state law. Public-source observations differ from direct probes; public availability and read-only operation alone do not establish legality.

Evidence before outreach · Part 1. Research date: October 6, 2026. This is educational information, not legal advice or clearance for a particular assessment.

TL;DR
  • A prospect domain review needs a method-specific assessment, not a blanket legal or illegal label.
  • SCOUTz separates public-source prospect intelligence from customer-authorized Microsoft 365 assessment.
  • Publicly indexed does not mean independently verified, currently exposed or compromised.
  • Read-only describes behavior. It does not establish authorization.
  • Commercial report emails need their own compliance controls.

Why does the collection method change the permission question?

An MSP can create unnecessary concern before the first meeting by describing public evidence as an intrusion. The opposite mistake is more serious: performing direct tests and describing them as passive research. Neither is fixed by replacing a word in the subject line.

Your evidence must support your description of how it was collected. If the report says no request was sent to verify an indexed observation, the sales representative must not say the team confirmed a live vulnerability. A useful first conversation starts with a bounded observation and a question about its relevance.

Can MSPs scan a prospect's domain before getting permission?

There is no sound nationwide answer that covers every activity described as a scan. The NCSL computer-crime survey, consulted October 6, 2026, identifies laws in all 50 states and expressly describes its material as comparative information rather than legal advice. The statutory questions include access, authorization, intent, information use and interference.

That does not mean every public lookup requires a signed agreement. It means that a broad label is a poor substitute for a description of actual requests. A lawyer needs to know which system received each request, what information was sought, which permissions applied and whether any restriction was encountered.

The unit of analysis is the action, not the product category. An indexed hostname, a DNS answer and a successful authenticated assessment do not establish the same facts. Do not merge them into one legal or technical claim.

ActivityWhat the evidence can establishBoundary to examine
Reading an existing public or licensed recordA source recorded an observationSource rights, date and accuracy
Querying published DNSThe queried record returned a particular answerRequest method, service and permitted use
Sending an HTTP or TLS requestA service responded to that interactionPublic-access scope, restrictions and request behavior
Enumerating ports or testing servicesA target responded to direct probesAccess, authorization and possible interference
Reading Microsoft 365 configuration through approved permissionsThe authorized review retrieved particular tenant evidenceConsenting person's authority and assessment scope

The table does not assign legal ratings. It identifies the facts that make the rows different.

What does a publicly indexed observation actually establish?

SCOUTz's free domain review, as described by the team, relies on public records and passive enumeration. Reports define indexed as publicly discoverable and state that no request was sent to verify the indexed observation. That qualification belongs beside the finding, not hidden at the bottom of a sales deck.

A public index can supply a starting point for a question. It cannot establish that the indexed resource is still available, belongs to the same operator or contains sensitive material. If those facts have not been checked, leave them unknown.

For every observation, preserve:

  • The source or source category.
  • The source's observation date, where available.
  • The date the report collected or retrieved the record.
  • Whether a request was sent to the prospect's system.
  • What was not verified.

The observation date and report date can differ. A fresh PDF does not make an old source observation current. If the source provides no observation date, say that explicitly rather than substituting the report's generation time.

Published DNS is not a view inside Microsoft 365

Published domain and email-security records provide outside-in evidence. They do not supply an internal inventory of a Microsoft 365 tenant. A report should not imply that public records prove the tenant's user permissions, internal settings or content.

Use the public record to identify the next question. Then obtain permission for any deeper assessment that needs protected tenant access. A second appointment is an opportunity to agree that scope, not an excuse to fill the gaps before the prospect arrives.

Passive enumeration needs a concrete definition

Ask what passive means in the actual workflow. Reading a third-party index without contacting the indexed service differs from sending a request to that service to see whether it responds. Calling both passive removes the distinction counsel needs.

Published DNS queries also involve an interaction with a DNS service. They are not the same as having no network activity anywhere. Describe the destination and request rather than claiming that public-source research never communicates with any computer.

The deeper SCOUTz Microsoft 365 assessment uses OAuth, the permission-based connection that grants an application defined access. The team's described workflow requires the prospect's authorization and full sign-up before that second-stage assessment.

That creates a meaningful boundary. It does not establish that every permission grant is sufficient for every legal purpose. You still need the correct tenant, an appropriate consenting person and an agreed use of the retrieved evidence.

Microsoft's consent guidance, consulted October 6, 2026, distinguishes user consent from administrator consent and explains that the permissions requested determine who can grant access. A successful sign-in is not a substitute for understanding those permissions.

Before deeper access, document:

  1. Which organization and tenant are in scope.
  2. Who authorizes the assessment and their role.
  3. What the assessment reads and excludes.
  4. Who receives the resulting report.
  5. When the authorization ends or can be withdrawn.

These are suggested risk controls. They are not a representation that every state mandates this exact form or that a completed form guarantees lawful access.

Proof: keep the report narrower than the evidence

The SCOUTz workflow described by the team includes no exploit checks, brute-forcing, authentication testing or content reads. The design is read-only. Reports are diagnosis only, with no built-in remediation upsell and no threatened disclosure as purchase pressure.

Those are useful product boundaries. They should appear as descriptions of actual behavior, not as universal defenses. Read-only access can still be unauthorized. A useful intention does not automatically authorize the request.

The Nmap legal discussion, consulted October 6, 2026, rejects a categorical answer about port-scanning legality and recommends written authorization before network scanning. It is practical technical commentary, not a current legal opinion for every jurisdiction.

Words that fit public-source evidence

An illustrative message for a report based only on public-source observations is:

We prepared dated observations from publicly discoverable sources. The report identifies the sources and states which observations were not independently verified. If useful, we can discuss whether they are relevant to your current environment.

This is sample wording, not a complete compliant commercial email. Add the required sender information, disclosures, postal address and opt-out mechanism where commercial-email rules apply.

Do not say you scanned the recipient's network if you did not. Do not say you found vulnerabilities when you found indexed references whose availability or implications remain unverified. If the method really included direct probing, changing the wording does not change that fact.

Is sending the report a separate commercial-email question?

A privately sent report can still be part of a commercial solicitation. A representative offering an MSP's services does not turn the email into a purely transactional message by attaching a security PDF.

Commercial purpose is defined in 15 U.S.C. § 7702(2)(A). Section 7704(a)(1)–(5) addresses transmission information, subjects, opt-outs, solicitation identification and postal addresses; § 7704(a)(3)(A)(ii) specifies at least 30 days of opt-out availability and § 7704(a)(4)(A)(i) specifies the 10-business-day post-request restriction. These citations use GovInfo's official 2024 edition, effective January 6, 2025, not a verified current 2026 compilation.

The FTC business guide explains these duties for individual and B2B messages. The detailed outreach guide separates the message requirements from the collection question.

Permission to review, permission to disclose and permission to keep marketing are separate records. Do not treat a yes to one as a yes to the others.

A practical pre-meeting boundary

For prospect preparation, use an approved list of public-source methods. Record the source and date, distinguish published records from direct target requests and leave unverified evidence unverified.

For direct tests or protected tenant access, use a separate authorization process. Agree the scope before making the requests, and do not expand it because the first results are interesting. If the prospect objects, stop the disputed direct activity and route the objection to the person responsible for the assessment.

For outreach, review the message and attachment together. The subject line, body and PDF should tell the same factual story. Commercial-email controls should apply even when a representative sends the message manually.

For an MSP seeking dated prospect intelligence rather than intrusive testing, SCOUTz provides an evidence-led starting point. It does not replace the MSP's judgment, the prospect's explanation or counsel's review of a defined workflow.

How does federal computer-access law fit?

The Computer Fraud and Abuse Act is an additional review layer, not a substitute for state law. 18 U.S.C. § 1030(a)(2)(C) addresses intentional unauthorized or excessive access that obtains information from a protected computer; § 1030(a)(5)(A)–(C) contains distinct damage provisions. Section 1030(e)(2)(B) defines the interstate-commerce connection for a protected computer, and § 1030(g) conditions civil actions on a violation, related damage or loss and specified factors.

Source limit: the federal text cited here is GovInfo's official 2024 edition, effective January 6, 2025. Later changes and controlling decisions have not been fully checked; this is not verified current 2026 legal clearance.

The DOJ Justice Manual § 9-48.000, B.3(8) and C instructs federal prosecutors on good-faith research and charging. It expressly creates no enforceable right or benefit. It is guidance, not immunity from civil claims, state law or other offenses; a sales purpose does not automatically qualify as good-faith research.

For the next decision, use the methods guide, the state research index and the authorization guide. They address different questions, not interchangeable permission checks.

FAQ

Is every unsolicited domain review illegal?

No blanket conclusion is justified. The method, authorization, jurisdiction and other statutory elements must be examined.

Does public availability prove authorization?

No. Public availability is relevant context, but it is not universal permission for every automated interaction or later use.

What does indexed mean in a SCOUTz report?

The team describes indexed as publicly discoverable, with no request sent to verify the observation. It does not establish current availability or compromise.

Does read-only mean an assessment is authorized?

No. Read-only describes the absence of intended changes, not whether access was permitted.

Does OAuth authorize the entire assessment?

OAuth grants defined technical permissions. The consenting person's authority, tenant scope and agreed purpose still need to match the assessment.

Does attaching a report exempt a prospecting email from CAN-SPAM?

No. The message's primary purpose controls, and commercial B2B email is covered.

Can an MSP claim a breach from an indexed observation?

Not without evidence establishing a breach. Keep the source observation separate from any unverified inference.

What should an MSP do before direct probing?

Define the exact methods and obtain appropriate authorization before proceeding. Counsel should review the workflow rather than a generic scan label.

One last thing

A finding is not permission to investigate further. The strongest handoff is often a clearly stated limit: this is what the public source showed, this is what remains unknown, and this is the next check the prospect can choose to authorize.

SCOUTz's methodology keeps evidence states and assessment boundaries visible. Indexed public observations are not automatically current, verified findings. The workflow facts described here come from the team and the published product boundary, not independent legal certification.

Sources

Statutes: 18 U.S.C. § 1030(a)(2)(C), (a)(5), (e)(2)(B), (g); 15 U.S.C. §§ 7702(2), 7704(a)(1)–(5), linked beside the claims above. Federal source: official 2024 edition, effective January 6, 2025; current-2026 comparison remains pending.

Court decisions: no case holding is asserted. A controlling and relevant decision review remains pending.

Agency guidance: DOJ Justice Manual § 9-48.000 and FTC CAN-SPAM business guidance, linked above. Guidance does not replace statutes or create immunity.

Other sources: NCSL is a comparative survey, Nmap is technical commentary, and Microsoft is platform-permission documentation. SCOUTz methodology and the team's stated workflow support the product boundaries. Sources were consulted October 6, 2026; consultation is not a legal-review sign-off.