Trusted security · Built from London
Products
Module 02

Domain Security.

The boring stuff attackers exploit first.

Email authentication, DNS posture, certificate hygiene. The fundamentals every security questionnaire asks about, verified continuously, mapped to controls.

At a glance
Module
02
Cadence
Hourly
Scoring axes
4
Compliance
SOC 2 · ISO · PCI
What we monitor

Inside the module.

Email authentication
SPF policy depth, DKIM key strength and rotation, DMARC enforcement (p=reject vs p=none), MTA-STS, TLS-RPT, BIMI eligibility.
DNS posture
DNSSEC chain validity, CAA records, NS health, zone walking risk, glue records.
Certificate hygiene
TLS chain, cipher suite strength, OCSP stapling, certificate transparency monitoring, expiry tracking with 60/30/7-day alerts.
Subdomain take-over risk
Dangling CNAMEs pointing to deprovisioned cloud resources, GitHub Pages, S3, Heroku.
Mail flow
Open relays, blacklist presence, suspicious MX records.
Scoring

How this module contributes to your rating.

Each factor below is a normalised sub-score (0–100). The module score is the asset-weighted geometric mean, a single missing header on your billing endpoint shouldn’t weigh the same as one on a marketing page.

DMARC enforcement
reject > quarantine > none, weighted by alignment
TLS posture index
cipher strength × cert age × OCSP
DNSSEC state
signed + valid chain + DS in parent
Subdomain take-over risk
count of dangling references × asset criticality

See Domain Security on your domain.

Get your free rating