Domain scorecard
Sample domain · public signals only · no internal access
I've talked a lot about the free domain review as a conversation starter, so it's time to open the hood. What does a read-only domain review actually collect, what won't it do, and why do the limits matter as much as the findings?
Start with the boundary. A read-only domain review collects technical information a company has already published to the public internet. The best analogy is walking past a building and noting what's visible from the sidewalk: the signage, whether the lights are on, and whether the front door is propped open. You learn real things from the sidewalk. You never set foot on the property.
The sidewalk view is readable in plain language. DNS records, which are public by definition, because the internet couldn't route mail or traffic without them. Inside those records live the email authentication settings, SPF, DKIM, DMARC, that say whether the company has told the world's mail servers how to reject impersonation. Certificate data, published openly in transparency logs, which shows whether the company's encryption is current and maintained. Services the company has exposed to the public internet, meaning things answering at their addresses that anyone can see are answering. And breach history tied to the domain, drawn from corpuses of already-public incident data.
Now the rules, which are not suggestions. The review never authenticates. No logins, no credential testing, and no guessing at passwords. It does not test a weakness or perform vulnerability testing. It reads companies, not people. We are not harvesting employee emails, scraping personal profiles, or building dossiers on humans. The subject is an organization's public technical posture, full stop.
Why so strict? Because the value of the scan depends entirely on it. The moment a scan crosses from observing to touching, three things break at once. It stops being something you can run before a relationship exists. It starts requiring the very consent it was designed to precede. And it puts the person running it, which in our world means an MSP with their brand on the report, somewhere no MSP should ever be standing. The rules aren't caution for its own sake. They're what makes the tool usable at all.
Most people miss that the limits create credibility. A read-only domain review can honestly answer one question, and it's a good question: is anyone minding the store? Missing email authentication, expired certificates, and forgotten exposed services are unattended-shop signals. What the review structurally cannot see is everything inside: identity, MFA coverage, mail rules, app permissions, and spending. Say both halves out loud. Here is what's visible from the street, and here is the honest boundary of what that means. The prospect learns something true about the company and learns that you volunteer the limits of your own data.
Observe, don't touch. Read what's published, claim only what it supports, and let the boundary itself do some of the selling. The scan opens the door. The rules are why you get to knock.