DNS, header and TLS checkers are free and plentiful — they'll grade whatever hostname you hand them. What they can't do is discovery and interpretation: mapping your estate from certificate transparency and DNS resolution, then telling you what actually matters versus what isn't yours to fix. On one real engagement, a vendor report claimed 13 IPs; our discovery found 15. Reconciling that gap is the job.
Subdomains and related assets from certificate transparency, public DNS and public datasets, including dangling CNAMEs pointing at deprovisioned third-party services.
WHOIS/RDAP, ASN and IP ownership records — separating what's yours from shared or third-party infrastructure.
SPF, DMARC and DKIM for recognised providers, plus STARTTLS support.
CAA, DNSSEC and reverse DNS consistency.
Hostname match, issuer, expiry, validity period, and whether a weak cipher was accepted during the handshake.
HTTPS redirect, HSTS, security headers, cookie flags, and server or technology disclosure.
Commonly exposed files and paths, public cloud storage naming, and what's already published on your own site.
Registered lookalikes of your domain, and whether any have live mail records.
No port scanning, no active cipher-suite enumeration, no vulnerability scanning or login attempts — nothing requiring access to your systems or authorisation. That's permanent by design, not a coverage gap. And no false comfort: this report says what we observed and what we couldn't verify, never that your perimeter is "clean."
Delivered as a document you can hand to an insurer, a customer, or a procurement panel.
Built for the business owner or ops manager who wants a clear answer, not another acronym-filled inbox.
Framework-agnostic — the findings aren't tied to Essential Eight, ASD Essentials or SMB1001, so it holds up whichever one you're actually working toward.