RECON SYSTEM // ONLINE

Discover your
cyber exposure

See your domain the way an attacker does — recon your external attack surface in under a minute.

resolving DNS records…

100 %
passive
0
contact
~60 s
scan

100% passive analysis based on public data. No active connection to your systems.

// recon scope18 modules

Attack surface

4
Subdomain EnumerationEvery subdomain is a way in. We map them all to surface forgotten or accidentally exposed services.Internet ServicesWhich of your servers' ports and services are visible from the Internet? A service exposed by mistake (database, admin panel) is a direct target.Exposed VulnerabilitiesCross-references your servers with Shodan's database to list known vulnerabilities (CVE) already public — exploitable without any scanning.Subdomain TakeoverA subdomain pointing to an abandoned service can be reclaimed by an attacker, who would then host malicious content under your own brand.

Impersonation & phishing

3
TyposquattingSpots look-alike domains and separates the ones you registered defensively from genuine third-party look-alikes — especially those configured for email phishing.Email SecurityWithout proper SPF/DKIM/DMARC, anyone can send emails in your name. It's the #1 vector for fraud and phishing.Anti-spam ReputationChecks whether your sending IPs or domain are on anti-spam blacklists. If listed, your legitimate emails land in spam or get rejected.

Leaks & secrets

6
Infected Machines (Infostealer)Detects staff or customer machines infected by an infostealer. Their credentials and session cookies are already circulating among cybercriminals.Dark Web ExposureSearches the dark web for credentials, combolists and mentions tied to your domain. Whatever leaks can be used to access your accounts.Code LeaksLooks for your domain in public code and verifies exposed secrets (API keys, tokens). A secret in cleartext is exploitable immediately.Historical URLsDigs through public web archives of your domain to spot forgotten sensitive files and backups (configs, exports, dumps).Email EnumerationLists your organization's publicly exposed email addresses — direct targets for phishing and credential stuffing.Document Metadata LeaksAnalyzes the metadata of your public documents (PDF/Office). It often reveals internal usernames and the software you use.

Configuration & encryption

5
DNS HealthChecks DNS hygiene: DNSSEC, server redundancy, key records. A fragile setup makes hijacking and outages easier.TLS CertificateInspects your certificate and TLS configuration. An expired certificate or outdated protocol breaks trust and exposes traffic.Domain RegistrationChecks your domain's expiry and transfer lock. An expired or unlocked domain can be bought back or hijacked.HTTP Security HeadersGrades the presence of defensive headers (HSTS, CSP…). Their absence exposes you to clickjacking, injection and HTTPS downgrade.Technologies & VersionsIdentifies the technologies and versions your site exposes. A disclosed version tells an attacker exactly which known flaws to try.

ReconScope — Free and responsible cyber diagnostic. Public data only. No intrusion.

How it works

From domain to diagnostic in three steps

No signup, no agent to install, nothing to connect. Just your domain name.

  1. 01

    Enter your domain

    Type your domain name and hit Analyze. Nothing to install, no account required to start.

  2. 02

    Live passive analysis

    Around twenty modules explore your public footprint — DNS, TLS, email spoofing, code leaks, typosquatting — and your exposure score climbs in real time.

  3. 03

    Score & actionable report

    Get a clear exposure score, findings prioritized by severity, and a shareable PDF report with the fixes that matter.

Sample report

What you get back

An illustrative preview — your own report reflects your real, live data.

EXAMPLE
642/1000
Exposure score
Email spoofing possibleHIGH

No DMARC policy — anyone can send email in your name.

TLS certificate expiring soonMEDIUM

Certificate expires in 8 days on a public endpoint.

Forgotten subdomains exposedMEDIUM

Two staging subdomains reachable from the Internet.

Fictitious example for illustration. Run a scan to see your real findings.

Safe by design

Passive, legal, and respectful of your data

100% passive

We never connect to or probe your systems. No intrusion, no active testing.

Public data only

DNS, TLS certificates, public registries and repositories — the same data an attacker can see.

Legal & ethical

Standard OSINT reconnaissance on publicly available information.

GDPR-friendly

Your data is never sold. Your email is used only to send your report.

Free

The full diagnostic is free, with no obligation.

Open-source tooling

Built on trusted open-source scanners (subfinder, trufflehog, and more).

FAQ

Frequently asked questions

Is this scan legal? Could I get in trouble?

Yes, it's legal. ReconScope is 100% passive: it only reads publicly available data (DNS, certificates, public registries) and never connects to or attacks your systems.

Do you need access to my systems?

No. There is nothing to install and no credentials to provide. We only observe what is already public on the Internet.

How long does a scan take?

About a minute. A first shock verdict appears in seconds, then the deep analysis completes the full report.

What do you do with my email address?

It is used only to send you your report. We never sell or share it.

Is it really free?

Yes. The full diagnostic and report are free, with no obligation.

Which tools power the scan?

Recognized open-source OSINT scanners such as subfinder and trufflehog, orchestrated into a single diagnostic.

Ready to see your exposure?

Get your cyber exposure score in under a minute — free and 100% passive.

Run my diagnostic