Domain.Posture

For security teams & consultancies

Scan every client domain from one place.

Give us up to five client domains and we’ll scan each one — DNS, email authentication, TLS, security headers, and AI-crawler policy — and send back one report covering all of them, with your firm on the cover. Free, and there’s nothing to buy afterwards.

  1. 1

    You tell us the domains

    Your firm's name and up to five client domains. Nothing to install, no access to anything of theirs — every check reads public DNS, TLS and WHOIS records.

  2. 2

    We scan every domain the same way

    DNS, MX, SPF, DKIM, DMARC, TLS, redirects, security headers, CORS, DNSSEC, MTA-STS, TLS-RPT, WHOIS, CT logs, and AI-crawler policy — per domain, with each finding mapped to the SOC 2 or ISO 27001 control it evidences.

  3. 3

    You get one report, with your name on it

    A single document across all five clients, gaps ranked by severity, ready to send or drop into an engagement. Yours to use however you like.

What the free report is not

It’s a working draft: real findings, but unsigned. The paid report is Ed25519-signed and dated, so your client’s auditor can confirm independently that it hasn’t been altered since you issued it — without an account, and without trusting either of us. Try verifying one.

Prepared from public records. It is not an authorised assessment of those domains, and we don’t contact your clients — ever.

Cover page of a sample signed domain security report

This is the shape of the document — one section per client instead of one domain. See a full sample.

Request your scan (5 domains, free)

Goes on the cover.

Client domains

Up to 5. Public DNS, TLS and WHOIS records only — the same data anyone can look up.

Where we send the workpaper.

Optional.

Free, no card. We don’t sell or share your address.