Sample domain · public signals only · no internal access
Disclose the review before presenting a finding, name the public source and observation time, explain that the report is a dated snapshot rather than ongoing monitoring, and make the evidence inspectable.
A long-time friend of mine, somebody whose read on this industry I trust more than almost anyone's, sent me a note after he saw the launch. Most of it was generous. One part stayed with me for two days.
He pointed out that the outside-in review runs before the first meeting, on a business that has not agreed to be looked at and does not know it is a candidate for anything. Everything the review checks is public. The owner on the other end may still see a stranger arrive with dated findings about the company. I had handled the accuracy half of that problem carefully. I had not handled the posture half. His exact words were that some people will feel scouted, and the word is right there in the name.
He is right. That deserves a direct answer.
What the public review actually reads
A domain review reads information a company already publishes to the public internet: DNS records, SPF and DMARC configuration, certificates, authoritative delegation, and a bounded HTTPS response. It does not require a login, an agent, or access to the company's internal systems. The SCOUTz report organizes those public observations, records when they were seen, and keeps the limits attached.
That is the technical boundary. It does not answer the question my friend raised. Nobody in a first meeting is thinking about protocols first. They are thinking about intent.
"How did you know?" and "Why were you looking?" are different questions
Most MSPs hope the prospect sees the preparation and says, "You did your homework." Sometimes that is exactly what happens.
The other reaction is quieter. An owner realizes someone reviewed the company's public configuration before a relationship existed. That reaction is not about whether the record is accurate. It is about attention being paid before permission was discussed.
I do not think that response is unreasonable. Public evidence does not remove the need for good judgment in how it is introduced.
Say it before the owner has to ask
Tell the prospect what was reviewed before presenting the first finding: "Before I called, I looked at what your domain publishes publicly. Here is the source, the time, and exactly what it showed."
Name the boundary just as plainly. The report in the room is a dated snapshot of public configuration. It is not hidden continuous monitoring, internal access, or a diagnosis of the whole business.
Then offer the receipt. If a finding concerns a mail record, show the record. If it concerns a certificate, show the certificate. A claim becomes easier to discuss when the person it concerns can inspect the source directly.
The review should not become smaller. The explanation should become better.
Asking permission before any public-record research would remove the reason this layer exists: helping the MSP arrive informed instead of starting from zero. The responsible answer is disclosure, scope, and evidence that can withstand inspection.
Some owners may still dislike it. That is useful information about the relationship, too. The MSP should be ready for the reaction instead of leaving the seller to invent an answer in the room.
Trust was the point before SCOUTz existed
The 3AM Test for MSPs asks who a client calls without hesitating when something breaks. That answer depends on trust built before the emergency. A public review should follow the same rule: say what you did, show what supports it, and name what remains outside the boundary.