Attack Surface
A per-domain deep dive across eight sections
A per-domain deep dive, split into eight sections in the sidebar. Every section works the same way:
- Domain picker (top right) — choose which of your domains to inspect. Your selection is remembered as you move between sections.
- Refresh button — re-fetches the section's data.
- Data comes from your Security Scans, and each section is populated only when its matching collection toggle is enabled in Scan Settings → Settings (the empty state tells you exactly which toggle to turn on, with a shortcut button).
The eight sections
- WHOIS — registrar, creation/update/expiry dates (with an expiry countdown chip), EPP status codes, registrant contact, abuse contact, name servers, DNSSEC, and the raw WHOIS record. Note: many registrars redact registrant details.
- DNS — all published records grouped by type (A, AAAA, MX, NS, TXT, CNAME, CAA, SOA) with TTLs and MX priorities, plus a per-type count summary.
- Subdomains — every hostname discovered under the domain, with status, source, and first-seen date. Filterable by name.
- Certificates — the TLS certificate(s) currently served (issuer, common name, SANs, validity window with an expiry chip, serial, algorithms) and the domain's Certificate Transparency history.
- Infrastructure — where the domain is hosted: IPs with ASN, ISP, cloud provider/region, and geography.
- Services — open ports and what's listening on them (protocol, service, product, version, banner). Ports that shouldn't normally face the internet (SSH, RDP, databases, etc.) are flagged as sensitive.
- Web — every HTTP/HTTPS endpoint: status code, server, redirects, detected technologies, response headers (with missing security headers highlighted — HSTS, CSP, X-Frame-Options, and friends), and cookie security flags.
- Email — mail security posture: MX records, and SPF / DKIM / DMARC / MTA-STS records each with a verdict — Valid / Weak / Invalid / Missing — plus specific issues (e.g. a soft-fail SPF).
Values throughout have one-click copy buttons on hover.
Which toggle feeds which section is listed in Scan Settings.