Spectari is an external attack-surface assessment service. You prove you own a domain, we look at it the way anyone on the internet could, and you get a written report of what is exposed and what to do about it.
This page describes how that works. It is a plain-language companion to the Authorization Agreement, which is the binding description of scope and method.
A point-in-time observation of a domain from the public internet. It uses no credentials, installs nothing, and requires no access to your systems. Everything in the report is something a stranger could have found on their own — the difference is that it has been gathered, checked and written down in one place.
spectari-verify=<token>. That record is your authorization,
and it is the only thing that permits a run.A list of problems is not much use on its own. Each finding in the report carries its own fix, naming the specific record or setting to change — and where the order of the work matters, the order is part of the advice:
_dmarc.<your-domain> with p=quarantine,
then p=reject.That word "then" is the part that matters. Publishing a strict policy before you know which of your own systems send mail on your behalf is how an organization stops its own invoices from arriving. Where a fix carries that kind of risk, the report says so and gives you the safe sequence rather than just the destination.
Findings are also grouped by cause. One misconfiguration visible on forty hosts is one finding with one fix, not forty — a report padded by its own fan-out tells you how wide a problem is, not how much work it is.
This is the method as it stands, not a permanent definition of the service. If it changes, this page and the Authorization Agreement change first, and nothing outside what they describe is ever run against your domain.
Every run produces a manifest listing each artifact it generated and that artifact's SHA-256 hash, so the report can be shown to be the one we sent and the evidence behind it can be verified independently.
The report states what was checked, when, and what was found — including where a check found nothing, which is deliberately distinguished from a check that was not run. An assessment that reports less than it should is worse than no assessment at all, because it leaves you confident.
The authorization record for each run is retained with the results, so it can always be established that the assessment was permitted and on what basis.
An assessment reflects what was externally observable at one moment. It is not exhaustive, and it is not a guarantee that your systems are secure. Discovery finds what public sources know about your domain, which is not necessarily everything that exists.
Your contact email, the domain you authorized, and the results — for 180 days, after which they are deleted. Sooner if you ask. We do not sell them. The full detail is in the Privacy Policy.
Domains today. Spectari is built to extend to other kinds of assessment, and one rule does not change as it does: you can only ever ask about yourself. Nothing is assessed without the person requesting it first proving they are the subject of it.
In development. Not open for business.