SAMPLE REPORT · REPRESENTATIVE DATA FOR A FICTIONAL DOMAIN
// FINAL REPORT · EXECUTIVE SUMMARY

Public attack surface for acme-corp.example

This is the board-readable view you receive the moment a free scan completes: what an attacker or auditor can see from the outside, ranked by what matters first.

68
RISK SCORE
34
SUBDOMAINS
19
OPEN PORTS
11
FINDINGS

FINDINGS BY SEVERITY

CRITICAL: 1HIGH: 3MEDIUM: 4LOW: 3

PRIORITIZED FINDINGS

CRITICALExposed admin panel on legacy subdomainconfirmed
admin.legacy.acme-corp.example:8443

Why it matters: An authentication portal for an internal tool is reachable from the public internet without IP allow-listing.

Recommended next step: Restrict access behind VPN/allow-list or take the host offline; rotate any credentials that may be exposed.

HIGHExpired TLS certificate on payment gatewayconfirmed
pay.acme-corp.example

Why it matters: The certificate expired 6 days ago; browsers will warn users and integrations may reject the connection.

Recommended next step: Renew and automate certificate issuance (ACME) to prevent recurrence.

HIGHDatabase port reachable from the internetprobable
198.51.100.24:5432 (PostgreSQL)

Why it matters: A database service responds to external connections, dramatically widening the attack surface.

Recommended next step: Bind the service to the private network and firewall the port; audit access logs.

MEDIUMMissing SPF/DMARC on active mail domainconfirmed
acme-corp.example (DNS)

Why it matters: Without SPF/DMARC the domain can be spoofed in phishing campaigns against staff and customers.

Recommended next step: Publish SPF and a DMARC policy (start at p=none, monitor, then enforce).

This is a sample. Run it on your own domain — free.

Start with an instant demo scan — no verification needed. Validate your domain to get this exact report for your real public surface. No card required.

Explore your public surface