Scout is live — open the app to verify your first domain and run a full scan.
ScoutExternal attack surface management · now live

See your domain the way
an attacker already can.

Scout maps what your organisation has exposed to the internet — hosts you forgot, software versions you never published, look-alike domains registered against your brand — and watches it for change. Start below with a free look at your email authentication (SPF, DMARC, DKIM): no signup, and nothing touches your systems.

We look up public DNS records only. We never connect to your mail servers or send email on your behalf.

01 / The problem

You cannot defend
what you never knew
was facing outwards.

Everything Scout works from is already public. The difference between you and someone hostile is not access to it — it is that they have been collecting it continuously and you have not.
01 — INVENTORY

Nobody has the whole list

Marketing stood up a landing page. A contractor left a staging host behind. A certificate names a hostname no one remembers issuing. Your attack surface is whatever is reachable — not whatever made it into the asset register.

Certificate Transparency · certs · page links
02 — VERSIONS

Version numbers you never meant to publish

Server banners, generator tags and asset paths announce exactly what you run. An attacker reads that against a CVE feed the day a disclosure lands. Most teams read it at the next assessment.

Matched against NVD & wpvulnerability.net
03 — DRIFT

A clean report expires the moment it is issued

Ports get opened for a migration and left open. Certificates lapse. A DNS record keeps pointing at a service that was decommissioned last quarter. All of it happens between point-in-time assessments.

Daily or weekly rescans, diffed
04 — BRAND

The domain that is not yours

A look-alike domain that has just had MX records configured is an invoice-fraud campaign being assembled. It sits on infrastructure you do not own, so nothing you run internally will ever see it.

Homoglyph · typo · combosquat · TLD swap
05 — SUPPLY

Your DNS names your dependencies out loud

CNAME and MX records spell out which providers you actually rely on — often more of them, and different ones, than the vendor spreadsheet says. So does a public breach catalogue when one of those providers is compromised.

Real CNAME & MX records · HIBP catalogue
06 — SPOOFING

Email that anyone can forge

SPF ending in ~all, DMARC still sitting at p=none, a DKIM selector that was never published. The checker at the top of this page finds these in seconds — which is rather the point, because so can anybody else.

Free above · no signup
02 / The console

Every domain, every host,
every finding — worst first.

One inventory across every domain you have verified, instead of a folder of PDFs that disagree with each other. Findings carry a status and an owner, so triage happens in the same place the evidence lives.
monitoring · daily

Findings

4 verified domains · sorted by severity
Open
Resolved
False positive
Domains monitored
4
all verified
Assets tracked
47
+6 this week
Needs attention
12
excl. informational
Critical / high
3
open
Severity
Finding
Host
Status
HIGH
Dangling CNAME — subdomain takeover
promo.acme.com
Open
HIGH
nginx 1.18.0 — 4 matched CVEs
edge-02.acme.com
Assigned
MEDIUM
DMARC policy set to p=none
acme.com
Open
MEDIUM
TLS certificate expires in 11 days
api.acme.com
Open
INFO
Port 22/tcp open — OpenSSH 8.9p1
edge-02.acme.com
Open

Detected changes

newpromo.acme.com appeared in a Certificate Transparency logtoday · 04:12 UTC
newacme-billing.co registered — MX records configuredyesterday · 22:40 UTC
changeedge-02.acme.com now serves nginx 1.18.0 (was 1.24.0)2 days ago
gone8080/tcp no longer reachable on api.acme.com4 days ago

Illustrative data. Every number and row above is produced by the scans you authorise.

03 / What Scout does

Discover. Understand.
Then keep watching.

Scout starts from a domain name and nothing else. Everything below is built from what that domain — and the hosts found underneath it — already tell the internet.
01 — DASHBOARD

Your external attack surface at a glance

Domains monitored, assets tracked, what needs attention, and open critical/high findings — in one summary rather than opening each domain in turn. Informational findings are counted separately, so a healthy domain does not read as fifty problems.

Across every verified domain
02 — ASSETS

The hosts underneath your domains

Every host Scout finds beneath a verified domain, discovered from Certificate Transparency logs, the certificate each domain serves, and the hosts its own pages reference. Tracks what is new this week and what has stopped answering.

Mark assets that handle sensitive data
03 — TECHNOLOGIES

Software you are running, and what is published about it

Products and versions identified from service banners, generator tags and asset paths, then matched against published advisories — NVD for servers and runtimes, wpvulnerability.net for WordPress plugins. Where no source covers a product, Scout says so rather than implying it is clean.

CVSS-scored · fixed version where one exists
04 — FINDINGS

One queue, worst first

Every finding across every domain in a single ranked list. Filter it, assign it, mark it resolved or a false positive in bulk, and export the selection — or everything matching your filter — as CSV.

Open · Resolved · False positive
05 — ATTACK PATHS

What reaching a host would actually take

Each path is one route to compromise: something that makes a host reachable, then something worth reaching once you are there. These are observed co-locations from real findings, not a simulation — and two vulnerable products on one host are two paths, because they are fixed separately.

Derived from your own findings
06 — THIRD PARTIES

The providers your DNS actually depends on

Read from real CNAME and MX records, so it reflects what is in production rather than what procurement has on file. Scout reports the dependency only — grading a provider would mean scanning infrastructure you neither own nor have authorised.

Detected via CNAME & MX
07 — BRAND PROTECTION

Look-alike domains, and breaches at providers you use

Sweeps for homoglyph, typo, combosquat, TLD-swap and bitsquat variants of your domains, and grades each one by how far it has been weaponised: registered, parked, configured to send mail, or serving a live site. Registrar and abuse contact come with it, because that is the only takedown route there is.

Breach data via Have I Been Pwned
08 — REPORTS

A snapshot that still says what it said

Generate a report for a domain and it keeps a copy of those findings, with a risk rating and an executive summary, at the moment it was issued. The next scan changes the console; it does not rewrite a report you have already sent to a customer or an auditor.

Draft → final
09 — MONITORING

Rescans on a schedule, and the diff between them

Set daily or weekly recurring scans per verified domain. Change is computed by diffing consecutive scans of the same domain, so a new host, a newly-open port or a downgraded software version surfaces as an event rather than something you have to spot yourself.

Off · Daily · Weekly
04 / How it works

A DNS record is the
whole onboarding.

No agent, no appliance, no VPN tunnel, no credentials handed over. If you can edit your own DNS, you can be scanning in the time it takes the record to propagate.
01

Add a domain

Enter a domain you own. Nothing is scanned yet — adding it only tells Scout what you are about to prove you control.

02

Prove you control it

Publish a one-time TXT record in that domain’s DNS and confirm. This is what authorises an active scan, and it is the only thing that does.

03

Run the scan

Scout probes open ports and services, TLS and certificate health, DNS hygiene, dangling CNAMEs and subdomain-takeover risk, and SPF/DMARC/DKIM posture — then fingerprints the software it finds and matches it against published advisories.

04

Stay covered

Turn on Monitoring for daily or weekly rescans. New exposure arrives as a change on the dashboard instead of waiting for someone to think to look again.

05 / Scope & authorisation

What Scout will not do,
and why that matters.

An attack surface tool that scans anything you type into it is a liability. The limits below are deliberate, and they are the reason your legal team will sign this off.
AUTHORISATION

Verified domains only

An active scan sends real traffic, so Scout will not run one against a domain you have not proven you control. The DNS TXT record is the authorisation — and recurring scans inherit it from the same verification, not from a checkbox.

One-time TXT record per domain
SCOPE

Outside-in, and nothing installed

Scout looks at your estate the way the internet does. Hosts on a private network are out of scope by design, and nothing is deployed into your infrastructure to reach them. For what happens inside — logs, dependency CVEs, traces — that is Obiguard SOC.

External surface · no agent
RESTRAINT

We report dependencies, we do not scan them

Scout tells you which providers your DNS relies on, and whether one of them appears in a public breach catalogue. It does not grade their security, because assessing a provider properly would mean scanning infrastructure you have no authority to authorise.

Dependency reported · not probed
06 / FAQ

Common
questions.

Don’t see what you’re looking for? Our solutions engineers respond within one business day.

Talk to an SE →
What is free, and what needs an account?01
The checker at the top of this page is free, needs no signup, and reads public DNS to tell you how your email authentication (SPF, DMARC, DKIM) looks from the outside. Everything else — asset discovery, active scanning, technology and CVE matching, attack paths, brand protection, reports and monitoring — runs inside the Obiguard platform against domains you have verified.
Does Scout need access to my systems?02
No. There is no agent, no appliance, and no credentials. Scout only sees what any host on the internet can see: DNS, certificates, what your services return when something connects to them, and public catalogues such as Certificate Transparency logs and Have I Been Pwned.
What authorises an active scan?03
Publishing a one-time TXT record in the domain’s DNS. That proves you control the domain, and it is what permits Scout to send real traffic to it. Recurring scans set up under Monitoring run on the authority of that same verification. A domain you have not verified is never actively scanned.
How is this different from Obiguard SOC?04
SOC works inside-out: your logs, metrics, traces, repositories and dependency CVEs, from systems you have connected. Scout works outside-in: what an attacker on the internet can reach and fingerprint without any access at all. Most teams find things in Scout that no internal tool could have shown them, precisely because those assets were never in an internal system to begin with.
Can Scout tell me if my company’s accounts were in a breach?05
Not directly. Brand Protection joins the providers your DNS depends on against Have I Been Pwned’s public breach catalogue, so it will tell you that a provider you rely on was breached. Confirming whether your own accounts appeared in it requires HIBP’s paid domain-search API, which Scout does not use — so it reports the exposure of the dependency, not of individuals.
What happens to a report after the next scan runs?06
Nothing. A report snapshots that domain’s findings at the moment it is generated and keeps its own copy, with a risk rating and an executive summary. Later scans update the console; a report you issued last month still says exactly what it said last month.
How many domains can I scan?07
Scout is built around multiple verified domains — the dashboard, findings queue and monitoring schedule all work across the whole set. Talk to us about scoping it for your organisation and we will size it against the estate you actually have.
07 / Get started

The lookup above is one domain.
Scout is the whole estate, watched.

Verify a domain with a single DNS record and Scout starts mapping what sits underneath it — hosts, software versions, look-alike domains, and everything that changes from one scan to the next.

Open Scout →Book a consultation