See your outside view
before attackers do.
A fixed-price external assessment that shows exactly what's publicly visible about your business — domains, email posture, exposed services, and Microsoft 365 identity signals — then turns it into an executive-ready report with a clear list of what to fix first.
What the internet already knows about you.
Recon runs the same external reconnaissance an attacker would — then does the part they never will: translate it into something your leadership can act on.
Email anyone can spoof
Missing or weak SPF, DKIM, and DMARC let attackers send convincing email as your domain — the root of most business email compromise and invoice fraud.
See the fix →Admin panels on the open internet
Management interfaces, RDP gateways, and legacy portals reachable from anywhere are the front door attackers try first.
See the fix →Forgotten subdomains
Old marketing sites, staging environments, and retired tools stay online for years, running software nobody has patched.
See the fix →Cloud left wide open
Storage buckets, dashboards, and shared drives that were meant to be internal but resolve publicly.
See the fix →Microsoft 365 identity signals
Tenant details, federation posture, and identity configuration are visible externally — and tell an attacker how to approach you.
See the fix →A history that never disappears
Certificate transparency logs and archived URLs preserve infrastructure you retired long ago.
See the fix →Four steps. No access required.
Scope your domain
You hand us one thing: your domain. No accounts, no installs, no internal access. We confirm scope in a one-page agreement and get to work.
Run external recon
We map your public footprint from the outside — subdomains, services, email and DNS posture, Microsoft 365 identity signals, and your historical web footprint.
Rank what actually matters
Findings are rated by real business impact, not scanner severity — so the list reflects your actual risk.
Get the report and fix first
You get the PDF, the readout call, and a prioritized list your team or MSP can start on immediately.
Fixed scope. Fixed price.
No hourly billing, no open-ended engagement. Pick the depth that fits.
- Full external attack-surface map
- Email & DNS posture (SPF, DKIM, DMARC)
- Microsoft 365 identity signals
- 15–20 page executive PDF
- Prioritized remediation list
- 60-minute readout call
- Everything in Snapshot
- Multiple domains & subsidiaries
- Historical infrastructure review
- Certificate transparency analysis
- Expanded OSINT artifacts
- Extended readout & Q&A
- Continuous surface monitoring
- Change alerts as exposure appears
- Monthly delta report
- Quarterly review call
- Priority response window
What's in the report.
The output is a clean PDF and a readout call — written so a managing partner, owner, or administrator can understand the risk and the plan without a security background.
Executive summary
The whole picture in one page — risk posture and priorities, plain English.
External attack surface
Every host, service, and port we could reach from the outside, with exposure ratings.
Email & DNS hygiene
SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI, DNS records, and certificate transparency.
Microsoft 365 posture
Tenant identification, federation, and the identity signals visible without credentials.
Ranked findings
Each finding with severity, evidence, business impact, and a specific fix.
Domain intelligence & history
Registration details, public footprint, and the historical record still indexed today — plus methodology and scope.
What buyers ask before they email.
What do you need from us?
One thing: your domain. No credentials, no agents, no installs. Scope is confirmed in a one-page agreement before any work starts.
Will this disrupt anything?
No. Recon is passive — built on publicly visible infrastructure and open-source evidence. We never touch your internal systems, so there's nothing to install and nothing to explain to your compliance team.
Is this a penetration test?
No. Recon maps what's publicly visible and ranks it by business impact — it doesn't attempt exploitation. It's the baseline that tells you whether deeper testing is even the right next spend.
How long does it take?
Most Snapshots are delivered within about 72 hours of scoping.
Who reads the report?
It's written for a managing partner, owner, or administrator — no security background required. Your team or MSP gets a prioritized fix list they can act on immediately.
Who is Recon built for?
50–500 person organizations on Microsoft 365 without an internal security team — the firms enterprise ASM platforms price out and ignore.