About this report
This is a passive, public-record assessment of [Business Name]'s external footprint — built from certificate transparency logs, DNS resolution and public registries only. No access to your systems, no credentials, nothing installed. It states what we independently observed and what we could not verify. It is not a security assessment and does not claim your perimeter is "clean."
4
Fail or not-determined results
Counts, not a score. This report doesn't grade or rate — it lists what was found.
Findings
Result: pass · fail · observation · not determined
Asset discovery
Observation
15 internet-facing assets identified via certificate transparency, public DNS and public datasets — 3 more than the domain list provided. 1 dangling CNAME found, pointing at a deprovisioned third-party service.
Observed 22 Sep 2026 via crt.sh + DNS resolution.
3 of 15 assets sit on shared infrastructure. 1 further asset confirmed as an unrelated third party and reframed as informational.
Observed 22 Sep 2026 via WHOIS/RDAP + ASN lookup. Reviewed by a person before issue.
DMARC policy: none (p=none). SPF: present, ~all (not enforced). DKIM: not checked (provider not recognised).
Observed 22 Sep 2026 via DNS TXT lookup. Not independently verified beyond DNS response.
CAA: not present. DNSSEC: not signed. Reverse DNS: consistent across active assets.
Observed 22 Sep 2026 via DNS TXT/DS lookup.
All active certificates currently valid. Nearest expiry: mail.[domain] in 11 days. No weak cipher accepted on any handshake observed.
Observed 22 Sep 2026 via TLS handshake inspection (single passive handshake per host — not cipher-suite enumeration).
HSTS not present on 2 of 15 assets. Preload-list eligibility not currently met.
Observed 22 Sep 2026 via HTTP response headers.
No commonly exposed files or paths found on primary assets. Cloud storage naming could not be checked for 2 assets from public sources alone.
Attempted 22 Sep 2026. Not determined is not a pass — it's recorded as its own result.
Lookalike domains
Observation
4 registered lookalike domains found. None currently have live mail records.
Observed 22 Sep 2026 via public domain registration data.
What we could not verify
Passive recon reduces but doesn't remove the chance of a false negative — a service can be missed if it doesn't respond the way our checks expect. Where we couldn't independently confirm something, this report says so rather than staying silent. Nothing here should be read as a guarantee.
What happens next
This report is yours under a perpetual licence — share it whole with your insurer, customers, auditors or IT provider. Mark any extract clearly as an extract. Not for public posting without our written consent, and not to be presented as a certification.
Staying current
Certificates expire, subdomains appear, DNS changes. A quarterly check-in is offered afterwards, from $660 inc. — never sold upfront as a plan.