RECON.SCAN
Domain Security Intelligence
Powered by SAilsy
Target Domains
ⓘ 0 domains loaded0 / 1000
What We Check
Email authentication
Can mail be sent as this domain? SPF, DMARC and DKIM, plus MTA-STS, TLS-RPT, BIMI, CAA and DNSSEC, and who runs their mail.
Web perimeter
Is anything in front of the public site? CDN, web application firewall and the security headers the browser is given.
Certificate
Is the certificate valid, publicly trusted and in date? From the public certificate logs.
Breach history
Do staff credentials for this domain appear in known breach data, how recently, and with passwords? Reported as could not check until the breach source is connected.
Exposed services
What is open to the internet: ports, remote access, databases and known vulnerabilities. Reported as could not check until the exposure source is connected.
Lookalike domains
Are near-identical versions of the domain already registered by someone else?
Web hardening
HTTPS enforcement, cookie flags, mixed content, security.txt, version disclosure, and the organisation's own one-line description of itself.
Attack surface
Subdomains from the certificate logs, and any pointing at abandoned cloud services an attacker could claim.
AI advisory layer
Every fact is decided in code. The AI writes only the advisory prose around them, and every sentence must pass a code check and an independent fact-checker before it is shown. Deep Intel adds a scoped web search for public sightings: job adverts, named tools, incident news, evidence of the adjacent capabilities.
Reading the Security Score
Each domain is scored 0-100 based on everything we find. Lower score = more gaps = bigger sales opportunity.
70-100 Well protected
40-69 Some gaps
0-39 At risk - strong opportunity
No results yet
Paste your prospect domains on the left and click Start Scan. Results appear here as each domain is checked.