PROSPECT INTELLIGENCEILLUSTRATIVE
SCOUTz product evidence supporting What a Domain Can Tell You—and What It Can’t.
What can a domain assessment establish?

A domain assessment can establish dated public configuration and exposure evidence, but it cannot prove internal identity, endpoint, recovery, or Microsoft 365 controls.

There's a whole industry built on scoring companies from the outside. Point a scanner at a domain, collect what's publicly visible, and produce a security grade. Some of these outfits will sell you a rating on any company on earth without that company ever knowing it was scored.

I want to be straight about what that kind of scan is worth, because SCOUTz offers one, free, and I don't want anyone confused about what it is.

From the outside, you can learn real things. Whether email authentication is set up, which says a lot about whether anyone is minding the store. What's exposed to the public internet that shouldn't be. Certificate hygiene. Breach history tied to the domain. These are honest signals, and they're enough to tell you whether a company has anyone paying attention.

The outside view cannot answer questions about identity, which is where modern compromise actually happens. You can't see whether admin accounts have MFA. You can't see the forwarding rule copying the CFO's inbox to a Gmail address. You can't see the OAuth app from 2021 with tenant-wide permissions and a credential that never expires. The most dangerous findings in any environment are invisible from the street, and any score that pretends otherwise is guessing.

That's why SCOUTz runs two tiers. The domain scan is free because it's worth exactly what a knock on the window is worth: enough to start a conversation, not enough to base decisions on. The real scan happens inside the tenant, with the client's explicit consent, reading configuration through authenticated access. Ground truth instead of inference.

The distinction matters more than it sounds. When an outside-in score is wrong, and they're wrong a lot, the MSP holding it looks foolish in the meeting. The client's IT guy says "that's not true, we fixed that last year," and your credibility leaves the room with him. Authenticated findings don't have that problem. The tenant said it, not you.

So use the domain scan for what it's for. Open doors with it. Just never confuse the knock with the visit. The deal, the remediation plan, the relationship, all of that lives inside, behind consent, where the truth is.