SCOUTz PROSPECT EVIDENCE · ONE DOMAINBuild the evidence-backed first look.
Review a prospect or client domain for public-facing email, DNS, certificate, web, and security-contact evidence. Every pass, gap, unread source, and scoring boundary stays visible. The result is free on screen; a business email is only required for the downloadable PDF.
5SCORES / UTC DAY
PER IP OR DEVICE
SEE EXACTLY WHAT THE FREE CHECK REVIEWS
Six practical security areas. Fourteen bounded public reads.
A useful first look for the conversation ahead—not a claim about controls hidden inside the business.
01Email authentication
SPF and DMARC presence, policy strength, and visible configuration.
02DNS trust
DNSKEY and DS reads to determine whether the DNSSEC chain is published.
03Certificate authorization
CAA records that name which certificate authorities may issue.
04Delegation resilience
Authoritative nameserver delegation and observable redundancy.
05Web response protections
One bounded HTTPS homepage read for supported security headers.
06Security contact
The RFC 9116 /.well-known/security.txt contact path.
WHAT THE FULL SCOUTz DOMAIN REVIEW ADDS
The public score is the doorway. The domain engine is the building.
The current domain-security workflow schedules 23 collector engines across the areas below, contributing to a platform registry of 156 distinct check types. A collector can execute multiple atomic checks and return evidence, no finding, an unavailable source, or an error; SCOUTz records that distinction instead of turning missing coverage into a pass.
DNS, certificates, and mail
DNS depth, certificate health, SPF, DMARC, DKIM signals, MTA-STS, TLS-RPT, DNSSEC, CAA, delegation, reputation, and IPv6 mail-path context.
External web surface
Subdomains, takeover signals, TLS posture, response headers, website compliance, CMS and technology fingerprints, and public-facing hardening context.
Brand and exposure
Lookalike domains, impersonation signals, source-labeled historical breach associations, passive perimeter intelligence, and supported public-exposure evidence.
Cloud doorstep
Public Microsoft 365 tenant discovery, managed-versus-federated identity signals, and the evidence boundary for requesting a customer-approved cloud review.
Technology and providers
Hosting, email-security, SaaS, telecom/UC, platform, vendor, and incumbent-management signals derived from public records and fingerprints.
Business context
Firmographic, entity, mobile-app, digital-presence, compliance-readiness, and public AI-governance signals that help an MSP prepare the right conversation.