Free tool

What an attacker seesof your domainwithout forcing anything.

Strictly passive reconnaissance: public DNS and unauthenticated endpoints only. No connection to your servers, no message sent, nothing that shows up in your logs.

No sign-up · Full result on screen · PDF report by email

What the scan looks at

  • Hosting, network and name servers
  • Mail routing and security gateway
  • SPF, DKIM, DMARC — presence, syntax, alignment
  • MTA-STS, TLS-RPT, DNSSEC, CAA, BIMI
  • Microsoft 365 tenant and authentication mode

About sixty seconds.

The on-screen result stays free and complete, with no address to leave.

Get this report by email

The PDF goes further than the screen: a summary written for your domain, what the findings mean for your business, and where to start.

This address will also receive our writing on Microsoft 365 and email security, once or twice a month. One-click unsubscribe in every message.

Your address is used for nothing else and is passed to no one.

And what is not public?

This scan only sees the outside. Your tenant configuration — privileged accounts, external sharing, legacy authentication, logging — needs read access and more than three hundred control points.

See the Microsoft 365 audit