A passive review of a company's public surface. It shows what an attacker would see before trying anything, without touching the client's systems.
Illustrative example · fictional dataThe company has a tidy public presence and its website works well. The main problem is email. Right now the domain can be spoofed, so a third party could send messages that appear to come from the company and use them to deceive clients or suppliers. It is a concrete fraud risk and it is quick to fix. Alongside it there are minor configuration adjustments worth closing to leave the surface clean.
One high email-fraud finding, plus pending configuration adjustments.
The diagnostic was done passively and on public information. No system was accessed, no passwords were tested and no load was placed on the client's servers. All work is carried out with written authorization and within the framework of Law 21.459 (the Chilean cybercrime law).
The domain's SPF, DKIM and DMARC records, to see whether it can be spoofed.
Name configuration, visible subdomains and public records.
HTTP security headers and the site's TLS certificate.
Visible traces in certificate transparency logs and search engines.
The domain has no DMARC policy published. In practice, anyone can send email that appears to come from the company. It is the usual gateway for email fraud, from a fake invoice sent to a supplier to a scam aimed at a client who trusts the sender.
The SPF record ends in ~all (softfail), which flags unauthorized email as suspicious but does not block it. It leaves room for illegitimate messages to still reach the recipient's inbox.
The site does not send several recommended security headers, such as HSTS and a content policy. It is not a flaw that gets exploited on its own, but it leaves the browser without protections that are standard today and makes other attacks on the visitor easier.
Internal subdomains show up in the public certificate transparency logs, for example test environments and admin panels. It is not a leak, but it gives an attacker a map of where to start looking.
The site's certificate is valid and well configured. It expires within a few weeks. It is not a risk today, but if renewal is not automated, a missed date would leave the site flagged as not secure.
Publish DMARC and tidy up SPF. It is the high finding and the one with the most impact for the least effort.
Add the missing security headers and confirm automatic renewal of the certificate.
Clean up unused subdomains and take internal environments out of public view.
Once fixed, monthly monitoring checks SPF, DMARC, TLS and exposure, and alerts the moment something changes. USD 30 per month.
The exposure diagnostic starts just like this example, with your real data and no commitment.
I want my diagnostic →