RECON SYSTEM // ONLINE

Discover your
external attack surface

See your domain the way an attacker does — recon your external attack surface in under a minute.

resolving DNS records…

100 %
passive
0
contact
~60 s
scan

100% passive analysis based on public data. No active connection to your systems.

// recon scope

33 modules

Attack surface

11
Subdomain EnumerationEvery subdomain is a way in. We map them all to surface forgotten or accidentally exposed services.Exposed surfaceWhich services are actually reachable from the Internet — and which belong to your hosting or email provider rather than to you.Exposed VulnerabilitiesCross-references your servers with Shodan's database to list known vulnerabilities (CVE) already public — exploitable without any scanning.Known Vulnerabilities (CVE)Maps the software versions your site reveals (nginx, Apache, PHP, jQuery…) to published CVEs, and flags the ones under active exploitation.IP Ranges & Hosting (ASN)Maps your IP ranges, network operator (ASN) and hosting country from public routing data.Third-party SaaS FootprintReveals the third-party SaaS vendors your DNS exposes (SPF includes, verification tokens) — each one a phishing pretext.Malicious Scanning From Your IPsChecks whether any of your IP addresses is a known malicious scanner — a strong sign of a compromised machine on your network.Subdomain TakeoverA subdomain pointing to an abandoned service can be reclaimed by an attacker, who would then host malicious content under your own brand.Public Cloud StorageLooks for cloud storage buckets named after your brand and left open: anyone who guesses the name can list and download everything inside.Open ports & CVEs (keyless)Lists open ports, exposed services and known CVEs on your IPs using Shodan's free, keyless InternetDB.Public urlscan.io intelSearches urlscan.io's public database for scans of your domain — sensitive pages, subdomains and hosts already visible to anyone.

Impersonation & phishing

4
TyposquattingFinds look-alike domains that could actually deceive — your brand name kept under another TLD, or a visual look-alike — then keeps only those registered after your own domain and showing signs of targeting you.Email SecurityWithout proper SPF/DKIM/DMARC, anyone can send emails in your name. It's the #1 vector for fraud and phishing.Anti-spam ReputationChecks whether your sending IPs or domain are on anti-spam blacklists. If listed, your legitimate emails land in spam or get rejected.Malware & Phishing ReputationChecks whether your domain is flagged for hosting phishing or malware — a sign it is compromised or its reputation is being damaged.

Leaks & secrets

10
Ransomware Leak SitesChecks whether your organisation appears on a ransomware gang's leak site — a public, verifiable sign of a past or ongoing compromise.Infected Machines (Infostealer)Detects staff or customer machines infected by an infostealer. Their credentials and session cookies are already circulating among cybercriminals.Dark Web ExposureSearches the dark web for credentials, combolists and mentions tied to your domain. Whatever leaks can be used to access your accounts.Code LeaksLooks for your domain in public code and verifies exposed secrets (API keys, tokens). A secret in cleartext is exploitable immediately.Public Forges (Postman, GitLab)Finds public Postman workspaces and GitLab projects published under your brand — API collections often embed tokens.Search-engine Exposure (dorking)Finds sensitive files and portals that Google has already indexed for your domain — read from the search index, never from your servers.Front-end secret leaksScans your homepage and first-party JavaScript for hard-coded API keys and tokens exposed to every visitor.Historical URLsDigs through public web archives of your domain to spot forgotten sensitive files and backups (configs, exports, dumps).Email EnumerationLists your organization's publicly exposed email addresses — direct targets for phishing and credential stuffing.Document Metadata LeaksAnalyzes the metadata of your public documents (PDF/Office). It often reveals internal usernames and the software you use.

Configuration & encryption

8
DNS HealthChecks DNS hygiene: DNSSEC, server redundancy, key records. A fragile setup makes hijacking and outages easier.Identity Provider & SSOIdentifies who handles your sign-in (Microsoft 365, Google Workspace, in-house SSO) and flags login endpoints you operate yourself.TLS CertificateInspects your certificate and TLS configuration. An expired certificate or outdated protocol breaks trust and exposes traffic.Certificate Transparency IntelligenceAnalyses all your certificates in public CT logs, flagging internal hostnames leaked to the world (jenkins., vpn., sap-preprod.).Domain RegistrationChecks your domain's expiry and transfer lock. An expired or unlocked domain can be bought back or hijacked.HTTP Security HeadersGrades the presence of defensive headers (HSTS, CSP…). Their absence exposes you to clickjacking, injection and HTTPS downgrade.Technologies & VersionsIdentifies the technologies and versions your site exposes. A disclosed version tells an attacker exactly which known flaws to try.Client-side Supply Chain (JS)Inventories the third-party scripts on your homepage and flags those loaded without integrity (SRI) — the Magecart risk.

ReconScope — Free and responsible cyber diagnostic. Public data only. No intrusion.

How it works

From domain to diagnostic in three steps

No signup, no agent to install, nothing to connect. Just your domain name.

  1. 01

    Enter your domain

    Type your domain name and hit Analyze. Nothing to install, no account required to start.

  2. 02

    Live passive analysis

    Around twenty modules explore your public footprint — DNS, TLS, email spoofing, code leaks, typosquatting — and your exposure score climbs in real time.

  3. 03

    Score & actionable report

    Get a clear exposure score, findings prioritized by severity, and a shareable PDF report with the fixes that matter.

Sample report

What you get back

An illustrative preview — your own report reflects your real, live data.

EXAMPLE
642/1000
Exposure score
Email spoofing possibleHIGH

No DMARC policy — anyone can send email in your name.

TLS certificate expiring soonMEDIUM

Certificate expires in 8 days on a public endpoint.

Forgotten subdomains exposedMEDIUM

Two staging subdomains reachable from the Internet.

Fictitious example for illustration. Run a scan to see your real findings.

Safe by design

Passive, legal, and respectful of your data

100% passive

We never connect to or probe your systems. No intrusion, no active testing.

Public data only

DNS, TLS certificates, public registries and repositories — the same data an attacker can see.

Legal & ethical

Standard OSINT reconnaissance on publicly available information.

GDPR-friendly

Your data is never sold. Your email is used only to send your report.

Free

The full diagnostic is free, with no obligation.

Open-source tooling

Built on trusted open-source scanners (subfinder, trufflehog, and more).

// guides

Understand what the scan finds

Three in-depth guides on the exposures we check most often — what they are, why they matter, and how to fix them.

FAQ

Frequently asked questions

Is this scan legal? Could I get in trouble?

Yes, it's legal. ReconScope is 100% passive: it only reads publicly available data (DNS, certificates, public registries) and never connects to or attacks your systems.

Do you need access to my systems?

No. There is nothing to install and no credentials to provide. We only observe what is already public on the Internet.

How long does a scan take?

About a minute. A first shock verdict appears in seconds, then the deep analysis completes the full report.

What do you do with my email address?

It is used only to send you your report. We never sell or share it.

Is it really free?

Yes. The full diagnostic and report are free, with no obligation.

Which tools power the scan?

Recognized open-source OSINT scanners such as subfinder and trufflehog, orchestrated into a single diagnostic.

Ready to see your exposure?

Get your cyber exposure score in under a minute — free and 100% passive.

Run my diagnostic