CYFRA/SCAN
REC · CAM 04
SECURITY SCORECARDPASSIVE SCAN · ES
// SURFACE SURVEILLANCE

HOW
EXPOSED
IS YOUR COMPANY?

One domain. One grade, A to E. No spin: what anyone who bothers to look can already see.

100% passive · public information only · we never touch your server
DNSEMAILTLS SUBDOMAINSHEADERSBREACHES
01
You type your domain. That is all: no account, no card, nothing to install.
02
We read what is already public about it: DNS records, certificates, the headers on your home page, breach databases.
03
You get a grade from A to E with the findings sorted by severity, plus the full report by email if you want it.
What this scan does NOT do It does not try passwords, does not exploit anything, does not send odd traffic at your server and does not log into any system. It is the same information anyone outside can see, only sorted and explained. Active testing is a separate service and it starts only once you sign a work order.
What it looks at, check by check
  • Emailwho is allowed to send email in your name (SPF).
  • Emailthe digital signature on your email (DKIM).
  • Emailprotection against spoofing (DMARC).
  • Emailencryption of the email you receive (MTA-STS and TLS-RPT).
  • Emailyour verified logo in your customers' inbox (BIMI).
  • DNSthe integrity of your DNS (DNSSEC and CAA).
  • TLSencryption on your website (the TLS protocol).
  • TLSyour certificate: that it is yours, valid and not expired.
  • Headersthe browser defenses your site turns on.
  • Subdomainsservers of yours that are publicly visible.
  • Breachesknown public data breaches.
  • Speedspeed and experience on a phone.
That is where the grade comes from: A 90 to 100 · B 80 to 89 · C 70 to 79 · D 50 to 69 · E below 50. Every check ends in one of three states, never two: verified with the raw evidence in plain sight, does not apply to this domain, or could not be verified — and that last one is said out loud, not counted as a pass. Every finding comes with its severity and what to do about it, and the full report reaches you by email if you ask for it.

Frequently asked

How much does the scan cost, and what do I need to run it?

Nothing. The scan is free. You type in the domain and that is it: no account, no card, nothing to install. The A to E grade shows up on screen in about two minutes and you do not have to leave any data to see it. If you also want the full report, we send that one by email, and that is the only point where an address is asked for.

Does this scan do anything to my server?

No. It is 100% passive: we only read information that is already public about your domain, meaning DNS records, certificates, the headers of your home page and public breach catalogues. We do not test passwords, we do not exploit anything and we do not send odd traffic to your servers. It is the same thing anyone can see from the outside, only sorted and explained. Active testing is a separate service and starts only once a work order is signed.

What does the A to E grade mean?

It is the twelve checks summed up in a single figure. A runs from 90 to 100 points, B from 80 to 89, C from 70 to 79, D from 50 to 69, and E is under 50. Every check ends in one of three states and never in two: verified with the raw evidence in plain sight, does not apply to this domain, or could not be verified. That last one is stated as such; it is never counted as a pass.

What do you do with my email, and how long do you keep it?

If you ask for the report we keep your email, the domain you scanned, the date and a summary of what the scan found. We use it for that and nothing else: it is not sold and it is not passed to anyone. We hold it for 6 months from the last contact and then it is deleted on its own. You can ask us to delete it sooner by writing to [email protected], and we do it within the following 5 working days. The full detail is in the privacy notice, at the foot of this page.

TARGET STANDBY
SCANNING_
TARGET
0%
··
DNS
EMAIL
TLS
SUBDOM
HEADERS
PERFORMANCE
BREACHES
NO INTRUSIVE TESTING · PUBLIC SOURCES ONLY
// — SCAN COMPLETE
EXPOSURE SCORE
0/100
ABCDE

What we found

BY SEVERITY · WITH WHAT TO DO
Send me the full report

Every finding explained, with the risk and how to close it. It lands in your inbox in 2 minutes.

We use your email only to send you this report. We do not sell it and we do not pass it to anyone. Privacy notice (Spanish)
Deep scan

This is only what shows from the outside. The deep scan actually tests: access controls, business logic and whatever an attacker would try.

ACTIVE TESTING · WITH SIGNED AUTHORIZATION