example.com
Last reviewed 2h ago
Start with a read-only exposure review for TLS, headers, DNS, and visible infrastructure. Sign in to turn the snapshot into verified assets, exposure history, and monitoring.
Scope
Public web assets
Input
One domain
Output
Ranked findings
Start A Public Exposure Review
Enter a public domain for a fast external exposure snapshot. No login needed.
Result format
Exposure score
A single number that summarizes externally visible risk across the review.
Attack-path ranked
The issues most likely to be exploited surface first. The rest do not bury what matters.
Continuous history
A one-time review is a snapshot. The workspace keeps the record so changes stay visible over time.
What it proves
We only surface signals that can be verified without credentials or assumptions. That keeps the result useful instead of noisy.
A lapsed certificate can interrupt secure access and expose users to browser trust warnings.
Missing security headers reduce the browser controls that help prevent framing and script abuse.
Misconfigured SPF, DKIM, DMARC, MX, or CAA records can weaken email trust and leave old dependencies behind.
Visible routing, redirect, and server signals make it easier to map your public footprint.
Findings specimen
The score reflects exploitability weight, not a flat count of issues. Findings are ordered by the risk they create, not just the control they touch.
Security score
Score / 100
Weighted across TLS, headers, DNS, and infrastructure signals.
Validated findings
Representative issues from a public exposure review
Missing content security policy
Without CSP, the browser has fewer controls to limit injected or untrusted script execution.
Certificate renewal window is narrowing
If the certificate expires, users will see trust warnings and secure connections can fail.
Edge stack is externally fingerprintable
Visible server and routing hints make external reconnaissance easier than it needs to be.
Weighted score
Reflects exploitability weight, not a flat count of findings.
Risk ordering
Entry-point risks surface first. Do not bury what an attacker would use first.
Workspace history
A score trending down is a perimeter opening. Track it before it becomes noise.
Workspace record
An exposure review is a snapshot. The workspace keeps ownership, history, and drift in the same place so you can act on the change, not the noise.
Assets — Verified domains tied to ownership, not guesswork.
Findings — Issues ranked by what matters first.
Trend — Score drift over time, so change stays visible.
example.com
Last reviewed 2h ago
shop.example.com
Last reviewed 2h ago
api.example.com
Last reviewed 2h ago
example.com
shop.example.com
api.example.com
2
Critical
7
High
14
Medium
Boundary rules
Public domains only
Validates internet-facing targets and blocks internal or private addresses.
Read-only analysis
The exposure review inspects externally visible signals without logging in, submitting forms, or making state-changing requests.
Rate-limited by design
Built-in limits keep free discovery safe, predictable, and resistant to abuse.
Get started
Start with a public exposure review. Keep the result in a workspace that knows what is owned, what is changing, and what needs attention first.