About Domain Posture
Domain Posture scans a domain's external security posture — DNS, email, TLS, headers, and its AI-crawler policy — and turns it into a dated, signed report. It runs the DNS, email-authentication (SPF, DKIM, DMARC), DNSSEC, TLS, and AI-crawler-policy checks behind that posture and returns a report you can hand to anyone: dated, signed, and re-checkable, with an alert the day something changes.
Who builds it
Arshad Ansari — founder, and the person who writes the code, answers the support email, and signs the reports. I'm a data engineer who has spent my career building data infrastructure for financial services, an industry where “prove it” is the default response to any claim. Domain Posture is that instinct applied to a narrow, unglamorous problem I kept watching people solve by pasting screenshots into spreadsheets.
I'm reachable and I'd rather you find me than a support alias: LinkedIn, or the contact form. If something we produced is wrong, telling me directly is the fastest way to get it fixed.
The service is operated by Hikmah Technologies, a data-engineering consultancy for financial services.
Why it exists
Free checkers tell you whether one record is valid. What they don't give you is the whole external picture — DNS, email authentication, TLS, security headers, and, increasingly, which AI crawlers and agents your domain lets in — as a dated artifact you can hand to a reviewer who has never heard of you: signed so it can't be quietly edited, saying what was true on a particular day, with each finding mapped to the SOC 2 and ISO 27001 controls a questionnaire is really asking about. That report — not the scoring — is the product.
The same engine is sold two ways: to the teams checking their own domains, and white-labelled to consultancies scanning and monitoring many client domains. The free domain dossier needs no signup, and every check is also callable from any MCP-capable client at /mcp.
How to check our work
Selling evidence obliges us to be checkable ourselves. Three ways, in increasing order of scepticism:
- The methodology documents every check, how severity is graded, and what we deliberately do not do.
- Trust & security scores our own domain with our own checks — including the rows that aren't clean yet — and lists every subprocessor that touches your data.
- Verify a report checks any pack we have issued against our published key. You can run that verification offline, on your own machine, without trusting this website at all.
What we don't claim
We scan a domain's external surface — DNS, email, TLS, and headers. We do not make anyone SOC 2 compliant, we do not replace an auditor, and a signature on a report proves only that the report is unaltered and came from us — never that the domain behind it is secure. The honest limits are written out on the trust page.