Authorized · External Exposure Assessment

See what the internet already sees.

Prove you own a domain, and Spectari finds the internet-facing hosts under it — including the ones you forgot — and checks what's exposed — forgotten hosts, spoofable email, TLS and certificate problems — and hands you a branded report you forward to a client, not a dashboard you log into.

Forgotten subdomains Email spoofability TLS & certificates Live service inventory Evidence manifest
01 — Prove ownership

One DNS-TXT record

You publish a token at your domain's apex. We re-verify it before every scan — no record, no scan.

02 — We observe

Authorized & non-intrusive

Passive discovery and safe checks against only the hosts that resolve under your verified domain.

03 — Get your report

A branded PDF, in your inbox

Plain-English findings, severity-ranked, with a SHA-256 evidence trail — ready to forward.

What you get

The outside view of your systems

A finished assessment of your external attack surface, packaged as a document you can forward to your team, your client, or your auditor — without anyone logging into a dashboard.

01

Full asset discovery

Every internet-facing subdomain and live service tied to your domain — including the staging box you forgot about.

02

Email spoofability

Whether anyone can send email that looks like it came from you (SPF / DMARC), with the exact records to fix it.

03

TLS & certificate hygiene

Expired, self-signed or mismatched certificates that break trust or throw browser warnings on your customers.

04

Live service inventory

What each host actually serves — status, page title, and detected technology — so you can see your real footprint.

05

Plain-English fixes

Every finding rated by severity with a concrete, prioritized remediation a developer can action today.

06

Client-ready PDF

A branded report with a SHA-256 evidence manifest and a documented authorization record — forward it as-is.

Pricing

Start with one assessment

Upgrade to continuous observation any time. Every plan includes the same authorization gate and the same evidence trail.

One-shot
$149
  • Full external exposure assessment
  • Asset discovery · email posture · TLS
  • Branded PDF, human-reviewed before it ships
  • SHA-256 evidence manifest

Ordering is by email for now. Card checkout is not switched on yet, so tell us the domain you want assessed and we will confirm the price, send you the DNS record that proves you control it, and take payment once you are happy.

Request an assessment
Spectari Watch · in development
$99 /mo per domain
  • Everything in one-shot, on a schedule
  • Weekly re-assessment + change alerts
  • Monthly client-ready PDF
  • New-asset detection — what changed
  • Cancel any time

Not available yet. Continuous monitoring is being built — we are not taking payment for it until it works. Tell us where to reach you and we will let you know when it is ready.

Notify me
Spectari Agency · in development
$349 /mo
  • Up to 10 client domains
  • Weekly observation on all of them
  • White-labelable monthly reports
  • "Authorization on file" per client

Not available yet. Same as Watch — it ships when the monitoring pipeline does.

Notify me

Questions

The things people ask first

Will this take down or slow my site?

Almost certainly not — but we will not answer this with a flat "never", because the authorization agreement you sign asks you to acknowledge a residual risk, and it would be dishonest to contradict it here. What actually happens per host is a DNS lookup, one ordinary HTTP request, and a second brief connection that reads your TLS certificate and closes without requesting anything — two short connections in total, rate-limited and scoped strictly to hosts under the domain you verified. We also make a few dozen DNS lookups about the domain as a whole, which reach your DNS provider rather than your servers and place no load on your site. There is no denial-of-service, fuzzing, brute-forcing, exploitation or vulnerability testing of any kind. That is a smaller load than a single visitor browsing your site.

Do I need to install anything?

Nothing. Everything is external. You add one DNS TXT record to prove ownership; that is the only setup on your side.

Does this include vulnerability and CVE scanning?

Not today. The current assessment is non-intrusive: asset discovery, email spoofability, TLS and certificate hygiene, and a live service inventory. Authorized active vulnerability testing is a separate service we are bringing online — we would rather tell you exactly what you are buying than imply more.

How is this different from a free security-rating site?

Free ratings guess from the outside and hand you a score. We run authorized checks against your own assets, with your documented permission on file, and give you a finished report with prioritized fixes and an evidence manifest — something you can hand to a client or an auditor.

What do I get, exactly?

A branded PDF: executive summary, email-spoofability verdict, prioritized findings with remediation, an inventory of the live services we found, and an appendix with methodology, your authorization record and a SHA-256 evidence manifest. A redacted sample is not published yet — ask us for one and we will send it.

Can you assess a domain I don't own?

No. Ownership verification is mandatory and re-checked before every scan, and we decline orders where authority looks doubtful. This protects you as much as us.