Scout maps what your organisation has exposed to the internet — hosts you forgot, software versions you never published, look-alike domains registered against your brand — and watches it for change. Start below with a free look at your email authentication (SPF, DMARC, DKIM): no signup, and nothing touches your systems.
Marketing stood up a landing page. A contractor left a staging host behind. A certificate names a hostname no one remembers issuing. Your attack surface is whatever is reachable — not whatever made it into the asset register.
Server banners, generator tags and asset paths announce exactly what you run. An attacker reads that against a CVE feed the day a disclosure lands. Most teams read it at the next assessment.
Ports get opened for a migration and left open. Certificates lapse. A DNS record keeps pointing at a service that was decommissioned last quarter. All of it happens between point-in-time assessments.
A look-alike domain that has just had MX records configured is an invoice-fraud campaign being assembled. It sits on infrastructure you do not own, so nothing you run internally will ever see it.
CNAME and MX records spell out which providers you actually rely on — often more of them, and different ones, than the vendor spreadsheet says. So does a public breach catalogue when one of those providers is compromised.
SPF ending in ~all, DMARC still sitting at p=none, a DKIM selector that was never published. The checker at the top of this page finds these in seconds — which is rather the point, because so can anybody else.
Illustrative data. Every number and row above is produced by the scans you authorise.
Domains monitored, assets tracked, what needs attention, and open critical/high findings — in one summary rather than opening each domain in turn. Informational findings are counted separately, so a healthy domain does not read as fifty problems.
Every host Scout finds beneath a verified domain, discovered from Certificate Transparency logs, the certificate each domain serves, and the hosts its own pages reference. Tracks what is new this week and what has stopped answering.
Products and versions identified from service banners, generator tags and asset paths, then matched against published advisories — NVD for servers and runtimes, wpvulnerability.net for WordPress plugins. Where no source covers a product, Scout says so rather than implying it is clean.
Every finding across every domain in a single ranked list. Filter it, assign it, mark it resolved or a false positive in bulk, and export the selection — or everything matching your filter — as CSV.
Each path is one route to compromise: something that makes a host reachable, then something worth reaching once you are there. These are observed co-locations from real findings, not a simulation — and two vulnerable products on one host are two paths, because they are fixed separately.
Read from real CNAME and MX records, so it reflects what is in production rather than what procurement has on file. Scout reports the dependency only — grading a provider would mean scanning infrastructure you neither own nor have authorised.
Sweeps for homoglyph, typo, combosquat, TLD-swap and bitsquat variants of your domains, and grades each one by how far it has been weaponised: registered, parked, configured to send mail, or serving a live site. Registrar and abuse contact come with it, because that is the only takedown route there is.
Generate a report for a domain and it keeps a copy of those findings, with a risk rating and an executive summary, at the moment it was issued. The next scan changes the console; it does not rewrite a report you have already sent to a customer or an auditor.
Set daily or weekly recurring scans per verified domain. Change is computed by diffing consecutive scans of the same domain, so a new host, a newly-open port or a downgraded software version surfaces as an event rather than something you have to spot yourself.
Enter a domain you own. Nothing is scanned yet — adding it only tells Scout what you are about to prove you control.
Publish a one-time TXT record in that domain’s DNS and confirm. This is what authorises an active scan, and it is the only thing that does.
Scout probes open ports and services, TLS and certificate health, DNS hygiene, dangling CNAMEs and subdomain-takeover risk, and SPF/DMARC/DKIM posture — then fingerprints the software it finds and matches it against published advisories.
Turn on Monitoring for daily or weekly rescans. New exposure arrives as a change on the dashboard instead of waiting for someone to think to look again.
An active scan sends real traffic, so Scout will not run one against a domain you have not proven you control. The DNS TXT record is the authorisation — and recurring scans inherit it from the same verification, not from a checkbox.
Scout looks at your estate the way the internet does. Hosts on a private network are out of scope by design, and nothing is deployed into your infrastructure to reach them. For what happens inside — logs, dependency CVEs, traces — that is Obiguard SOC.
Scout tells you which providers your DNS relies on, and whether one of them appears in a public breach catalogue. It does not grade their security, because assessing a provider properly would mean scanning infrastructure you have no authority to authorise.
Don’t see what you’re looking for? Our solutions engineers respond within one business day.
Talk to an SE →Verify a domain with a single DNS record and Scout starts mapping what sits underneath it — hosts, software versions, look-alike domains, and everything that changes from one scan to the next.