WORKING DOMAIN TOOLS · TRANSPARENT ROADMAP

Use the working tools. See the next diagnostics.

Run the public domain score and use 11 local DNS and email-security generators on this website now. The 48-tool catalog makes the next diagnostics visible without treating unfinished tools as available or routing anyone into the product application.

ANSWER-FIRST PROSPECT CONTEXT

Know what the signal means before you use it.

What is MSP prospect risk intelligence?

MSP prospect risk intelligence combines legitimate public company context with source-labeled external security evidence so a managed service provider can prioritize research, explain why a conversation may matter now, and prepare better discovery questions without claiming purchase intent.

What can SCOUTz learn from public domain evidence?

The free public review can observe supported email-authentication records, DNS trust, certificate authorization, authoritative delegation, selected web-response protections, and the security-contact path. It cannot establish internal identity, applications, devices, recovery, people, or operational controls.

Does a public domain review prove that an organization is insecure?

No. It is a bounded outside-in observation with visible coverage and unknowns. SCOUTz uses it to support a useful question and an evidence-backed first conversation, not to declare an organization secure, insecure, or ready to buy.

ON-SITE MSP TOOL CATALOG

Use what works now. See what is next.

The public score and local record generators live on this website. The catalog shows the next five diagnostics before the wider planned set, and never sends visitors to an unfinished product route.

11Working generators
5Next diagnostics
32Further planned
48Tool catalog

AVAILABLE NOW

11 browser-based generators

Prepare a local draft, then let the MSP validate, approve, publish, and verify the change.

GeneratorsAvailable here

SPF record generator

Build one sender policy from approved services, hosts, and IP ranges.

GeneratorsAvailable here

DKIM key and record generator

Generate a 2048-bit key pair in the browser or format a provider public key.

GeneratorsAvailable here

DMARC policy generator

Stage monitoring, quarantine, and reject with reporting and alignment controls.

GeneratorsAvailable here

MTA-STS policy generator

Create the DNS marker and hosted TLS policy for the exact inbound mail routes.

GeneratorsAvailable here

BIMI checker and generator

Build the brand record and validate its DMARC, logo, and certificate prerequisites.

GeneratorsAvailable here

TLS-RPT record generator

Route SMTP transport-failure reports to monitored mail or HTTPS destinations.

GeneratorsAvailable here

CAA record generator

Authorize normal and wildcard certificate issuers and an incident contact.

GeneratorsAvailable here

TLSA / DANE record generator

Build a certificate association for the right service, port, and DNSSEC-backed host.

GeneratorsAvailable here

security.txt generator

Publish an RFC 9116 disclosure contact with a monitored address and current expiry.

BUILDING NEXT

Five public checks with the clearest first use

DNS, registration, DNSSEC, DMARC, and web-protection checks are the next diagnostic surfaces planned for this website.

DNS & routingComing soon

DNS lookup

Read common and advanced record types without turning a failed lookup into absence.

DNS & routingComing soon

DNSSEC validator

Distinguish published signing data from a fully validating parent-to-zone chain.

DNS & routingComing soon

WHOIS / RDAP lookup

Review registrar, dates, status codes, and redaction through modern RDAP.

Email authenticationComing soon

DMARC checker

Validate policy, alignment, reporting, subdomain behavior, percentage, and rollout state.

Web securityComing soon

Web headers, cookies and resources

Inspect browser defenses and cookie or resource behavior on the final response.

FULL ROADMAP

32 further diagnostics remain planned.

They include deeper passive, browser, authorized, and infrastructure-dependent checks. They stay visible without being presented as working tools.

Why are some tools marked Coming soon?

SCOUTz only labels a utility available when it works on this public website and has a truthful evidence boundary. Authorized, infrastructure-dependent, and deeper diagnostic workflows remain visible as the roadmap—but they do not point to unfinished application routes.

SCOUTz PROSPECT EVIDENCE · ONE DOMAIN

Build the evidence-backed first look.

Review a prospect or client domain for public-facing email, DNS, certificate, web, and security-contact evidence. Every pass, gap, unread source, and scoring boundary stays visible. The result is free on screen; a business email is only required for the downloadable PDF.

5SCORES / UTC DAY
PER IP OR DEVICE
SEE EXACTLY WHAT THE FREE CHECK REVIEWS

Six practical security areas. Fourteen bounded public reads.

A useful first look for the conversation ahead—not a claim about controls hidden inside the business.

01

Email authentication

SPF and DMARC presence, policy strength, and visible configuration.

02

DNS trust

DNSKEY and DS reads to determine whether the DNSSEC chain is published.

03

Certificate authorization

CAA records that name which certificate authorities may issue.

04

Delegation resilience

Authoritative nameserver delegation and observable redundancy.

05

Web response protections

One bounded HTTPS homepage read for supported security headers.

06

Security contact

The RFC 9116 /.well-known/security.txt contact path.

No email gate. One domain at a time. No bulk scan, login, port sweep, history, monitoring, or claim that an organization is secure.

WHAT THE FULL SCOUTz DOMAIN REVIEW ADDS

The public score is the doorway. The domain engine is the building.

The current domain-security workflow schedules 23 collector engines across the areas below, contributing to a platform registry of 156 distinct check types. A collector can execute multiple atomic checks and return evidence, no finding, an unavailable source, or an error; SCOUTz records that distinction instead of turning missing coverage into a pass.

DNS, certificates, and mail

DNS depth, certificate health, SPF, DMARC, DKIM signals, MTA-STS, TLS-RPT, DNSSEC, CAA, delegation, reputation, and IPv6 mail-path context.

External web surface

Subdomains, takeover signals, TLS posture, response headers, website compliance, CMS and technology fingerprints, and public-facing hardening context.

Brand and exposure

Lookalike domains, impersonation signals, source-labeled historical breach associations, passive perimeter intelligence, and supported public-exposure evidence.

Cloud doorstep

Public Microsoft 365 tenant discovery, managed-versus-federated identity signals, and the evidence boundary for requesting a customer-approved cloud review.

Technology and providers

Hosting, email-security, SaaS, telecom/UC, platform, vendor, and incumbent-management signals derived from public records and fingerprints.

Business context

Firmographic, entity, mobile-app, digital-presence, compliance-readiness, and public AI-governance signals that help an MSP prepare the right conversation.

MSP SELLER

Lead with a real, dated configuration trigger.

Use the score and its explicit coverage as a reason to ask a useful question instead of a claim that the organization is insecure or shopping for an MSP.

MSP OPERATOR

Move from observed gap to a controlled change.

Use the local fix lab to prepare the draft, rollout notes, rollback boundary, and final validation plan for an authorized MSP-managed client.

COURTESY DOMAIN FIX TOOLS · MSP WORKFLOW

Domain Fix Lab

Prepare an MSP-managed client change and preserve the rollout boundary. Everything here runs locally in the browser: no domain query, no scan, no monitoring, no DNS change, and no data sent to SCOUTz.

TXT · @
v=spf1 include:spf.protection.outlook.com -all

Inventory every legitimate sender before publishing -all.

THE ON-SITE TOOLKIT

Use what works today. See the honest roadmap.

The public score explains what bounded evidence supports. The local fix lab prepares safe drafts. The larger diagnostic catalog stays visible without pretending unfinished tools are available.

1 public score

A bounded, factual domain-configuration review with visible coverage and unknowns.

11 working generators

Copy-ready drafts stay in the browser until the MSP validates, approves, publishes, and verifies the change.

5 next diagnostics

The highest-value public checks are visible before the wider planned catalog.

32 further planned

Deeper passive, browser, authorized, and infrastructure-dependent diagnostics stay clearly labeled.

Why does SCOUTz offer these tools as a courtesy?

A useful first finding should come with a safe next step. Public and local tools help an MSP teach and prepare; active tests keep customer consent explicit. These utilities remain independent from completed assessment scores.

THE SCOUTz EVIDENCE JOURNEY

Start small. Add depth only when the relationship earns it.

Each layer answers a larger question without pretending the earlier layer saw more than it did.

01

TRY

Fourteen bounded public reads become seven scored components plus a source-labeled record appendix with a visible evidence boundary.

Run the courtesy score →
02

DIAGNOSE

Choose from 48 tools, including 11 local generators, browser analyzers, passive checks, and customer-approved active tests.

Find the right tool →
03

ASSESS

Build a broader, source-labeled Domain Review with MSP-ready evidence and reporting.

Explore full SCOUTz →
04

DEEPEN

With customer consent, move into a read-only Microsoft 365 review. Permission, license, provider, source, and collector gaps remain visible instead of being counted as clean.

See the cloud review →
One public score is not a complete security review.

The score uses public DNS, authoritative delegation, one bounded HTTPS homepage read, and the RFC 9116 security-contact path. It does not use tenant evidence, a port sweep, bulk scanning, history, monitoring, exploitation, or production changes. Unread evidence is excluded and never counted as clean. Think clipboard and flashlight, not an RMM wearing a fake mustache.

Continue the evidence journey in Open Beta →

SCOUTz OPEN BETA

Point SCOUTz at the question. Walk in with a defensible answer.

Bring a real MSP workflow and see how SCOUTz turns evidence into the next defensible action. The review runs without an agent or install and never changes configuration automatically.

SCOUTz prepares the conversation. The relationship and the sale stay yours.