
Public security data records what a source made discoverable. Active probing sends new requests to a target to learn how it responds; the difference matters for evidence quality, authorization and how you describe a prospect report.
Evidence before outreach · Part 2. Research date: October 6, 2026. Educational information, not legal advice.
- Public security data versus active probing is a distinction about actual requests, not branding.
- SCOUTz prospect intelligence separates indexed observations from independently verified findings.
- A DNS query and a third-party index lookup are different collection methods.
- A TLS certificate from an index differs from a certificate retrieved in a live connection.
- Read-only requests still require analysis of access and authorization.
Why must an MSP distinguish observation from testing?
A seller wants a reason to call. A security practitioner wants to know how the evidence was obtained. A business owner wants to know whether anyone interacted with the company's systems.
One report must answer all three without exaggeration. If a source recorded a hostname, that establishes a source observation. It does not establish that your team accessed the hostname, that the service is currently reachable or that it exposes sensitive information.
Where do public security data and active probing differ?
The distinction begins at the request. Identify the service that received it, the information requested and the result returned. Then describe the method at that level.
- Public-source observation: information obtained from an openly published record or a third-party source under its applicable access and licensing terms. It establishes what that source recorded, not necessarily the target's current condition.
- DNS lookup: a query to a resolver or authoritative DNS service for published records, such as address, mail-routing or text records. It is a service request, but not an authenticated internal tenant review.
- Direct HTTP request: a request to the target's web service for a resource or response metadata, including headers. It contacts the target even when it makes no intended changes.
- Direct TLS connection: a handshake with the target service to observe the certificate or supported connection behavior. Reading a certificate-transparency index instead does not make that live connection.
- Port enumeration: packets or connection attempts to identify which target ports respond; banner collection then requests or receives service-identification information. Neither establishes exploitability by itself.
- Exploit testing: crafted requests or payloads intended to test whether a vulnerability can be triggered. It differs from version observation and requires its own authorization and harm analysis.
For the legal question these definitions support, start with the permission overview. These are conduct descriptions, not universal legal classifications.
| Method | Interaction | What remains unknown |
|---|---|---|
| Reading a third-party index | Request goes to the index provider | Whether the indexed target still matches the record |
| Reviewing certificate-transparency records | Request goes to the record source | Whether the referenced service currently presents that certificate |
| Querying published DNS | Request goes to a DNS service | Internal configuration and the business reason for the record |
| Reading HTTP headers from a live service | New interaction with the target service | Whether broader configuration or application behavior is secure |
| Inspecting a certificate through a live TLS connection | New connection to the target service | Whether all other services have the same configuration |
| Enumerating ports or service banners | Direct reconnaissance requests | Permission for those requests and their operational effects |
| Testing an exploit or authentication behavior | Direct security testing | Authorization for the particular test and its possible effects |
These are method categories, not legal ratings. A tool can combine several rows. Evaluate each collector rather than approving the entire product under one adjective.
Evidence: preserve the collection path
For each observation, record the chain from the source to the report. A source timestamp tells you when a provider observed something. A retrieval timestamp tells you when your report obtained it. Neither should be substituted for the other.
SCOUTz's free domain review, as described by the team, relies on public records and passive enumeration. Its reports state that indexed means publicly discoverable and that no request was sent to verify an indexed observation. Preserve that qualification when you export or discuss the result.
Indexed is not verified
An indexed reference can be useful even when it is not independently verified. It gives you a question to ask. The problem begins when a summary drops the qualifier and presents it as a live exposure.
Use distinct labels for distinct states:
- Source observation: the record exists in the identified source.
- Current response: a permitted request returned the described result.
- Interpretation: the observation has a possible security consequence.
- Confirmed condition: an authorized review established the relevant facts.
These labels are a suggested reporting discipline, not a claim that SCOUTz uses these exact interface fields. The point is to keep observation and interpretation separate.
DNS is a published service, not an internal assessment
A published DNS answer can describe a domain's visible email or naming configuration. It cannot establish every control inside the organization. Do not infer a complete Microsoft 365 security posture from records outside the tenant.
A public DNS query is also a request to a service. Avoid the inaccurate claim that public-source research makes no requests anywhere. The narrower, useful statement is that a particular indexed resource received no verification request.
TLS evidence depends on the source
A certificate retrieved from an existing index supplies historical or recorded context. A certificate presented during a new TLS connection supplies evidence about that connection. A report that simply says certificate checked hides the collection method.
State whether the result came from an index or from a live connection. If the workflow did not perform the latter, do not borrow its evidentiary strength in the sales email.
Does read-only mean passive or authorized?
A request can be read-only and still interact directly with a target. Port enumeration can seek information without changing configuration, but it is not the same activity as reading someone else's existing index. HTTP and TLS observations also involve actual target interactions when collected live.
Read-only answers whether you intended to change data. Passive answers a different question about collection. Neither establishes legal permission.
The NCSL survey, consulted October 6, 2026, describes differences among state computer-crime provisions. Access, authorization and interference require their own analysis. The Nmap legal discussion also rejects a universal answer about port-scanning legality.
For product review, ask counsel about concrete request categories, not whether a tool is a scanner. Marketing vocabulary cannot make a direct request indirect or an unauthorized action authorized.
What should an approved-method inventory record?
A practical method inventory should identify what each collector does. Keep the inventory separate from a sales brochure so the technical owner can change it without altering the evidence trail.
For each collector, document:
- The source or destination category.
- Whether it contacts the prospect's service.
- The request type and information sought.
- Any credentials or permissions required.
- What it does not test or retrieve.
- The evidence fields included in the report.
An inventory is only useful if new collectors are reviewed before they are deployed. If a feature changes from reading an index to verifying an indexed resource, revisit the assessment. The legal and reporting assumptions have changed even if the report looks identical.
Keep the deeper assessment separate
SCOUTz's Microsoft 365 assessment, according to the team, uses OAuth and requires prospect authorization and full sign-up at the second stage. The team's description excludes exploit checks, brute-forcing, authentication testing and content reads.
Those boundaries distinguish the product from intrusive testing. They do not prove that every possible use is legally cleared. Record the authorized tenant, the person granting permission and the agreed use of the findings.
Words that preserve the evidence
Use descriptions that fit the collection method:
| Instead of | Use when supported |
|---|---|
| We scanned your network | We reviewed published records associated with your domain |
| This resource is exposed | This source indexed the resource; current availability was not verified |
| Your company is compromised | The report contains an observation that needs context, not evidence of compromise |
| We confirmed your tenant is insecure | The authorized review retrieved the listed configuration evidence |
The alternative wording is not a script to hide conduct. If your team did perform direct probing, disclose the actual method and evaluate whether it was authorized. Accuracy is the rule in both directions.
FAQ
Is public security data always passive?
No. Querying a published service still involves a request. Identify whether the request went to a third-party source, DNS service or the prospect's target service.
Is a read-only request an active probe?
It can be. A read-only request can interact directly with a target even when it does not intentionally change data.
Does a certificate index prove a live service is secure?
No. An indexed certificate observation does not establish a service's current availability or broader security.
Does indexed mean a vulnerability was confirmed?
No. SCOUTz describes indexed observations as publicly discoverable without a verification request to the indexed resource.
Can DNS records show internal Microsoft 365 permissions?
Not by themselves. Internal tenant evidence requires an appropriately authorized assessment.
Does calling a product prospect intelligence change the law?
No. The actual collection method controls the analysis, not the product category.
What should an MSP record for each collector?
Record the source, destination, request type, permissions, timestamps and evidence limits. Use the inventory to review changes before deployment.
One last thing
A useful report can stop at unknown. Resisting an unapproved verification request preserves the difference between preparing for a conversation and investigating someone else's systems.
For cross-jurisdiction questions, use the state-law index. For protected tenant access, use the assessment authorization guide. SCOUTz's methodology and trust boundary distinguish observed, inferred, verified and unknown evidence; do not collapse those states into a verified vulnerability.
Which federal provisions require separate review?
18 U.S.C. § 1030(a)(2)(C) addresses intentional unauthorized or excessive access obtaining information from a protected computer. Section 1030(a)(5)(A)–(C) addresses distinct damage conduct, and § 1030(b) covers attempts and conspiracy to commit an offense. The definitions in § 1030(e)(2), (6), (8) and (11) also matter. A method label does not determine whether these elements are met.
The cited federal text is the official 2024 edition, effective January 6, 2025; later changes have not been fully compared. The DOJ charging policy, Justice Manual § 9-48.000 B.3(8), C is guidance to prosecutors, not immunity or a permission grant for prospecting.
Sources
Statutes: 18 U.S.C. § 1030(a)(2)(C), (a)(5), (b), (e), linked above; official 2024 edition, effective January 6, 2025, not verified current 2026 text.
Court decisions: no decision holding is asserted; method-specific precedent review remains pending.
Agency guidance: DOJ Justice Manual § 9-48.000, linked above, with no enforceable-right promise.
Technical and product sources: Nmap legal commentary and NCSL comparative survey, linked above, are not statutes or legal clearance. The team's workflow description, SCOUTz methodology and trust pages support the product boundary, not a blanket passive-only claim for every external collector. Sources consulted October 6, 2026.
