Tool 14

What can an attacker see about your domain right now?

Two live checks against a domain you own — whether anyone can send mail as it, and what its TLS estate is serving — read together as the outside view an insurer, a regulator or a prospective client would form.

In short
Two of the ten risk vectors behind a security rating can be read from outside in under a minute: email authentication, from public DNS, and TLS configuration, from a handshake with each live host. Both are configuration rather than architecture, which makes them the cheapest findings to clear. The other eight need an observation window and an attributed estate, which is what the Rating Report supplies.

Check your domain

Enter the domain and a work email address on it. Two checks run at once: the DNS records that decide whether anyone can send mail as you, resolved in your own browser, and a TLS handshake with every live host we can find under the domain, from our servers. Both finish in under a minute on most estates.

Two live checks against a domain you own. The email half resolves public DNS from your browser; the TLS half connects from our servers, which is the only way to read a certificate.

A worked example, below. This is the reading for the specimen domain, so the page answers before you enter anything. Run the check above to replace it with your own.

2 of 10risk vectors read — worked example. 10 exposures and 7 gaps found.
  • DEmail authenticationp=none tells receiving servers to take no action on mail that fails. It is the correct place to start — it turns on the reports you need before enforcing — but it is a monitoring configuration, and a domain left here is as forgeable as one with no record at all. This is where most domains stop.7 records read
  • FTLS and certificates9 findings a browser would warn about, across 6 live hosts.6 hosts probed
  • Eight more vectorsBotnet infections · Spam propagation · Malware servers · Unsolicited communications · Critical vulnerability management · Open ports · Web application headers · DNSSECnot read here

The letters are ours, not Bitsight’s. A Bitsight vector grade is a percentile against every company it rates, normalised for size, and cannot be derived from one domain. What these encode is the basis printed beside each one.

These two are configuration rather than architecture, which makes them the cheapest findings to clear. The other eight need an observation window and an attributed estate — which is what the Cyber Risk Rating Report supplies, scored 250–900 and benchmarked against your sector.

Why the email has to match

This is the only tool here that will not answer for any input, and the reason is worth stating plainly. Every other page in this set computes something it already knows: the registers, the thresholds and the clocks are on the page, and the calculator is a convenience. This one opens connections to your servers from ours. That is the single thing on this site that spends somebody else’s resources, and an anonymous scanning endpoint is worth more to an abuser than it is to a visitor.

So the address has to sit on the domain being scanned, or beneath it — you@yourcompany.in may scan yourcompany.in and mail.yourcompany.in, and nothing else. Containment rather than a comparison of registrable domains, because getting the latter wrong fails in the dangerous direction: India alone has co.in, ac.in, gov.in and several more, and a suffix list that misses one turns a match on your domain into a match on everybody’s.

Two vectors out of ten

A Bitsight Security Rating is calculated from ten risk vectors. This reads two of them, and the result says so where it shows the grades rather than in a footnote. The two it reads are the two that can be observed from outside without a window of history: a DNS lookup answers the first, and a handshake answers the second.

The eight it does not read:

  • Botnet infections
  • Spam propagation
  • Malware servers
  • Unsolicited communications
  • Critical vulnerability management
  • Open ports
  • Web application headers
  • DNSSEC

Those need an attributed estate and an observation window — which host belongs to which company, and what it was doing over months rather than at the moment of a probe. Neither is derivable from one domain by us or by anyone else, and a free tool claiming otherwise is claiming something it cannot have.

The letter grades here are this tool’s own. A Bitsight vector grade is a percentile against every company Bitsight rates, normalised for size. What these encode is printed beside each one, so the arithmetic is yours to check.

What to do with the result

Both vectors here are configuration rather than architecture, which is what makes them worth clearing first. They are also both covered by Dynamic Remediation — Bitsight’s on-demand rescan — so credit for a fix arrives on request rather than at the next observation.

  • Email authentication. Publish the transport records first, because they break nothing, and move DMARC to enforcement last, because moving it before the reports are clean is what breaks invoicing on a Monday morning. The email spoofing check gives the record to publish for each finding in that order.
  • TLS. Protocol versions first — setting a minimum of TLS 1.2 on one host usually clears three findings at once. Certificates second, because each is its own reissue and they parallelise. The SSL estate check lists every affected host.
  • Then the other eight. The Cyber Risk Rating Report is where they come from, with the rating itself and the benchmark against your industry. It is complimentary and needs no access to your systems.
Every instrument cited here was verified against the issuing regulator's own notification on .

Questions this page answers

Why do I have to use an email address on the domain I am checking?
Because the scan is not a lookup — it opens connections to your servers from ours, which is the one thing on this site that costs a third party something. Requiring an address on the domain being scanned, or beneath it, means the tool only ever points at an estate the person asking can show they belong to. Every other tool here answers for any input, because the answer is a fact the page already holds.
Our group sends email from a different domain to the website. Can we still use it?
Not through this tool, and that is a deliberate limit rather than an oversight. Containment is what makes the scan authenticated, and loosening the comparison to cover group domains would mean accepting an assertion instead of a demonstration. Request the Cyber Risk Rating Report instead — it covers the whole attributed estate, needs no address match, and reads all ten vectors rather than two.
How much of a security rating do these two checks cover?
Two vectors out of ten, and they are the two cheapest to fix. Email authentication and TLS configuration are both settings rather than architecture, and both are covered by Bitsight’s Dynamic Remediation, which means credit for a fix arrives on request instead of at the next observation. The other eight — botnet infections, spam propagation, malware servers, unsolicited communications, critical vulnerability management, open ports, web application headers and DNSSEC — need an observation window and an attributed estate.
Are the letter grades the same as Bitsight’s?
No, and the result says so where it shows them. A Bitsight vector grade is a percentile against every company Bitsight rates, normalised for size. Nothing derived from one domain can be that. The letters here encode what was found on your estate, with the basis printed next to each one so the arithmetic is yours to check.
What does the scan actually do to our servers?
The email half resolves public DNS records from your browser against Google and Cloudflare, and never reaches us. The TLS half looks for subdomains in the Certificate Transparency logs, keeps the ones that resolve, and completes a TLS handshake with each — the same exchange a browser performs before loading a page. It observes what a server volunteers and never acts on it. Nothing is submitted, nothing is authenticated against, and no port other than 443 is touched.
A clean result — does that mean we are secure?
It means two classes of finding are absent from what could be seen. Subdomain discovery is a floor rather than an inventory: a host with a private certificate and an unguessable name appears in no public log, and DKIM selectors cannot be enumerated at all. A finding here is evidence; an absence of findings is evidence only about what was found.

This tool is one skill out of sixteen.

What runs on this page is the browser-sized version of entity-scope, a skill in BitScoreCoWork — our MIT-licensed Claude plugin. The full version runs against your own Bitsight tenancy and works from your measured attack surface rather than a form. The source is public, so you can read exactly what it does before you run it.

Read the source The Applied AI practice

Knowing the rule is the easy half.

This page tells you what you owe. It cannot tell you what an attacker already sees. Your organisation has a security rating calculated from signals visible from outside — request the complimentary Cyber Risk Rating Report and find out what it says. No agent, no system access, no questionnaire.

Request my rating All free tools