Countdown until the UK analogue phone switch-off on 31 January 2027.Is your business affected?
Free Tool

Free External Attack Surface Scan

See your business the way an attacker does. The email-security checks — SPF, DKIM, DMARC — run instantly against public DNS. The full external scan (exposed services, subdomains, certificate issues) is released only after you prove you control the domain.

Quick answer

This free security scan checks your domain's email security instantly — SPF, DKIM and DMARC, read live from public DNS — and offers a full external attack-surface report covering exposed services, subdomains and certificate issues. The full report requires domain-ownership verification via a DNS TXT record first: attack-surface detail is never shown for a domain the requester hasn't proven they control, so the tool cannot be used to reconnoitre other companies.

Scan your domain

Enter your business domain. The email-security checks (SPF, DKIM, DMARC) run instantly against public DNS — real lookups, live results. The full attack-surface report needs you to prove you control the domain first.

How the full report works

undefined

Instant email checks

SPF, DKIM and DMARC are public DNS records — the scan reads them live and explains what each result means for spoofing and phishing exposure.

undefined

Verify your domain

Add a one-line DNS TXT record to prove you control the domain. This is the gate that stops anyone using the tool to scope out a company they don't own.

undefined

Get the full report

Our team runs the full external scan — powered by SurfaceLoop, AMVIA's attack-surface platform — and emails you the report with plain-English remediation notes.

What the scan looks at

SPF

Whether receiving servers can tell who is allowed to send email as your domain — missing SPF makes invoice-fraud spoofing trivial.

DKIM

Whether your outbound mail is cryptographically signed, checked across the common Microsoft 365, Google and ESP selectors.

DMARC

The policy that decides what happens to mail that fails authentication — monitoring only (p=none) still lets spoofed mail through.

Exposed services

Full report: internet-facing services and ports that shouldn't be public — remote desktop, databases, admin panels.

Subdomains & certificates

Full report: forgotten subdomains and expiring or misconfigured certificates — the classic quiet ways in.

Verification-gated by design

Attack-surface detail is only released for domains verified by DNS TXT challenge. Email checks show public records only.

Exposure you'd rather not manage alone?

AMVIA runs managed email security, managed firewalls and continuous attack-surface monitoring for UK businesses — the fix for what this scan finds.

Attack surface scan questions