Free External Attack Surface Scan
See your business the way an attacker does. The email-security checks — SPF, DKIM, DMARC — run instantly against public DNS. The full external scan (exposed services, subdomains, certificate issues) is released only after you prove you control the domain.
Quick answer
This free security scan checks your domain's email security instantly — SPF, DKIM and DMARC, read live from public DNS — and offers a full external attack-surface report covering exposed services, subdomains and certificate issues. The full report requires domain-ownership verification via a DNS TXT record first: attack-surface detail is never shown for a domain the requester hasn't proven they control, so the tool cannot be used to reconnoitre other companies.
Scan your domain
Enter your business domain. The email-security checks (SPF, DKIM, DMARC) run instantly against public DNS — real lookups, live results. The full attack-surface report needs you to prove you control the domain first.
How the full report works
Instant email checks
SPF, DKIM and DMARC are public DNS records — the scan reads them live and explains what each result means for spoofing and phishing exposure.
Verify your domain
Add a one-line DNS TXT record to prove you control the domain. This is the gate that stops anyone using the tool to scope out a company they don't own.
Get the full report
Our team runs the full external scan — powered by SurfaceLoop, AMVIA's attack-surface platform — and emails you the report with plain-English remediation notes.
What the scan looks at
SPF
Whether receiving servers can tell who is allowed to send email as your domain — missing SPF makes invoice-fraud spoofing trivial.
DKIM
Whether your outbound mail is cryptographically signed, checked across the common Microsoft 365, Google and ESP selectors.
DMARC
The policy that decides what happens to mail that fails authentication — monitoring only (p=none) still lets spoofed mail through.
Exposed services
Full report: internet-facing services and ports that shouldn't be public — remote desktop, databases, admin panels.
Subdomains & certificates
Full report: forgotten subdomains and expiring or misconfigured certificates — the classic quiet ways in.
Verification-gated by design
Attack-surface detail is only released for domains verified by DNS TXT challenge. Email checks show public records only.
Related services and tools
Attack Surface Management
SurfaceLoop — continuous monitoring of your internet-facing assets, as a managed service.
Email Security
Managed email security: the fix for SPF, DKIM and DMARC gaps, plus filtering and phishing defence.
Cyber Essentials readiness assessment
Twenty questions against the five certification controls.
All free security tools
The full toolkit: attack surface scan, readiness assessments, certificate checker and more.
Exposure you'd rather not manage alone?
AMVIA runs managed email security, managed firewalls and continuous attack-surface monitoring for UK businesses — the fix for what this scan finds.
Attack surface scan questions
Everything about your business that is visible and reachable from the internet: domains and subdomains, exposed services and ports, mail configuration, certificates and login panels. It is what an attacker enumerates first, because it requires no access and no malware — just looking.
Yes. SPF, DKIM and DMARC are public DNS records — the tool reads them live when you click scan and explains what each result means. No account, no email address required for that tier.
Because a detailed map of a company's exposed services is exactly what an attacker wants, we never show attack-surface detail for a domain the requester hasn't proven they control. Verification is a one-line DNS TXT record — if you can edit the domain's DNS, you control the domain.
Externally discoverable exposure for your verified domain: internet-facing services, subdomains, certificate issues and open administrative panels, with plain-English notes on what each category means and what to do about it. It is run by our team on SurfaceLoop, AMVIA's attack-surface management platform, and emailed to you.
The scan observes what is already publicly visible — DNS records, certificate transparency, internet-wide service data. It is reconnaissance of your public footprint, not a penetration test: nothing is exploited, nothing is logged into, and nothing touches systems that aren't already internet-facing.
Missing SPF or DMARC doesn't mean you've been breached; it means your domain is easier to impersonate — and domain impersonation is how most invoice fraud starts. The fixes are DNS records, not products, and our email security service configures them properly as routine work.