Add one DNS TXT record to prove you own the domain, then we run a deeper active scan — exposed secrets and config — and send you a private report. Free beta, no payment.
✓Finds exposed .env / .git / backups and other sensitive files
✓Verified by a DNS TXT record, so only you can run it on your domain
Aggregate grade across 18 checks. Auditors typically flag any High-severity finding.
Pass
14
Warn
4
Fail
0
What an auditor would flag first
low
DMARC
p=quarantine — receivers send to spam
SOC 2 CC6.7ISO 27001 A.5.14
low
TLS certificate
cert expires in 73 days
SOC 2 CC6.1ISO 27001 A.8.24
low
Security headers
3 security header(s) missing
SOC 2 CC6.6ISO 27001 A.8.23
Need this as an artifact your auditor can verify?
Your x.ai scan flagged 4 low findings. The signed report covers the apex plus up to 100 CT-discovered subdomains, Ed25519-signed and ISO-timestamped, delivered in 10–30 minutes.
Signed or refunded within 30 days — the same evidence a consultant bills $500+ in hours to assemble.
Why it matters: MX records direct inbound mail. Misconfiguration silently breaks email delivery and lets attackers stand up parallel MX hosts for spoofing campaigns (ISO 27001 A.8.21).
Why it matters: DMARC binds SPF and DKIM into an enforceable policy (quarantine or reject) and surfaces spoofing attempts via aggregate reports. `p=none` or absent means spoofing succeeds silently (SOC 2 CC6.7).
Recommendations
Upgrade to p=reject once your SPF and DKIM pass rates are consistently high
Why it matters: SPF tells receiving servers which hosts may send mail for the domain. Without it, any sender can forge the envelope-from — the primary mechanism behind business-email-compromise (SOC 2 CC6.7).
DNSSEC not configured — no DS or DNSKEY records found
Why it matters: DNSSEC cryptographically signs DNS responses, blocking cache-poisoning attacks. US federal civilian agencies are required to enable it under OMB M-22-09 (NIST SC-20).
Recommendations
Enable DNSSEC in your DNS provider's control panel and add the resulting DS record at your registrar
Why it matters: MTA-STS forces inbound SMTP to use TLS and refuse downgraded connections. Without it, an in-path attacker can strip TLS and read mail in plaintext (SOC 2 CC6.7).
Why it matters: DKIM signs outbound mail so receivers can detect tampering. Missing selectors or rotated-away keys break DMARC alignment and let receivers downgrade trust (ISO 27001 A.8.24).
Why it matters: Without authoritative A or AAAA records on the apex, the domain is unreachable. Missing baseline DNS shows up in vendor reviews as evidence of unmanaged infrastructure (SOC 2 CC6.6).
Why it matters: A valid current TLS certificate is the baseline for data in transit. Expiry, weak chain, or hostname mismatch break HTTPS and fail PCI 4.2.1 / SOC 2 CC6.1.
Why it matters: Bare HTTP requests must redirect to HTTPS without dropping the user mid-chain. Plain-text fallback or open redirects fail PCI 4.2.1 and feed phishing chains (SOC 2 CC6.6).
no CORS headers — cross-origin requests blocked by default
Why it matters: Overly permissive CORS (wildcard with credentials, or reflected origin) lets any origin read authenticated responses from this domain. OWASP A05 misconfiguration territory (NIST AC-4).
origin
https://domainposture.com
method
GET
preflight status
403
access-control-* headers
access-control-allow-origin
—
access-control-allow-methods
—
access-control-allow-headers
—
access-control-allow-credentials
—
access-control-max-age
—
access-control-expose-headers
—
no access-control-* headers returned — site does not advertise CORS to this origin
Why it matters: Whether a domain publishes an llms.txt — an emerging convention that gives AI agents a curated markdown index of the site's content, the way robots.txt and sitemap.xml guide search crawlers. Its presence signals a site that intentionally guides AI agents rather than leaving them to scrape blindly. Informational in an audit: it shows AI-readiness maturity, not a security control.
Why it matters: Whether a domain publishes a security.txt (RFC 9116) at /.well-known/security.txt — the standard, machine-readable channel that tells security researchers how to report a vulnerability. Without one, a researcher who finds an issue has no published route to disclose it responsibly, so reports get dropped or go public. A published disclosure contact is a baseline expectation in a security review, which is why its absence is flagged.
HTTPS surface reachable (robots ✓, sitemap ✗, title ✓)
Why it matters: Public files — robots.txt, sitemap.xml, head meta — are what attackers see first during reconnaissance. Misadvertised paths, stale sitemaps, and verbose generators leak more than intended (ISO 27001 A.8.9).
robots.txt
present
User-agent: *
Allow: /
Disallow: /tools/
User-agent: GPTBot
User-agent: ChatGPT-User
User-agent: PerplexityBot
User-agent: ClaudeBot
User-agent: Google-Extended
User-agent: Applebot-Extended
Allow: /
Disallow: /tools/
Sitemap: https://x.ai/sitemap.xml
# Content Signals (draft) — declare AI/search usage preferences
# See: https://contentsignals.org/
Content-Signal: ai-train=no, search=yes, ai-input=no
# Guides are written to be cited; allow answer-engine input on this tree only.
Content-Signal: /bot/guides ai-train=no, search=yes, ai-input=yes
AI crawlers allowed — no agents blocked in robots.txt
Why it matters: Whether a domain has told the major AI crawlers (GPTBot, ClaudeBot, Google-Extended, PerplexityBot, and others) anything in robots.txt. With no policy declared, those agents default to crawling the site for model training and answer-engine retrieval. This is a content-governance stance, not a vulnerability — an audit records the declared position so a buyer knows whether the vendor has made a deliberate choice about AI access to its content.
Why it matters: Every certificate issued for this domain is published in Certificate Transparency logs — including subdomains you may have forgotten. Unknown subdomains in CT are pre-disclosed attack surface (ISO 27001 A.8.16).
Why it matters: Registrar and expiry tell auditors the domain is owned, current, and not about to lapse. An expired or about-to-expire domain fails business-continuity evidence (SOC 2 A1.2).