External domain risk monitoring for SMEs, consultants and MSPs. Scan a domain's security posture, tell a genuine site from a convincing fake, and check a suspicious email — then monitor what matters, run a live breach incident against the 72-hour ICO clock, and turn it all into plain-English fixes and client-ready evidence.
I want to…
Check the security posture of any domain — 50+ external checks
No password. No credit card. Just your email to receive results.
One sign-in, both apps — Free, Pro or MSP covers security and authenticity. No second subscription.
Hosted on security-certified infrastructure providers.
50+
Security checks
< 60s
Scan time
Clear
Risk rating
40+
Intel sources
Sample Intelligence Providers
MyDomainRisk combines browser safety reputation from Google Web Risk, breach exposure data from Have I Been Pwned, internet exposure data from Shodan and infostealer exposure intelligence from HudsonRock, alongside IP reputation, page threat analysis, public DNS, certificate transparency, phishing, malware and ransomware intelligence feeds.
A concise view of the external guidance and benchmarks covered by our checks. This is supporting evidence, not certification.
Read the full comparisonStrong overlap
Supporting evidence
Comparative analysis last reviewed: 17 August 2026
Surface Compliance
Every scan includes advisory compliance cards alongside the main risk rating — externally visible evidence only, not a certification audit.
UK & EU — Article 32 technical advisory. ⓘ What's checked?
Advisory only. A passing score does not constitute GDPR compliance — organisational measures, DPAs, and data retention policies are out of scope.
PCI DSS 4.0 advisory review — applies wherever card payments are taken. ⓘ What's checked?
PCI DSS 4.0 Surface
Advisory only. Not a PCI DSS certification — formal audits, cardholder-data-environment scoping, and organisational controls remain out of scope.
California privacy advisory review — relevant if you serve California residents. ⓘ What's checked?
US Privacy — CCPA / CPRA
Advisory only. Not a legal CCPA compliance assessment — organisational controls and legal obligations remain out of scope.
Externally observable signals for both lenses — the security posture of a domain you own, and the authenticity of one you do not — with no special access or agent required.
Included free
Detects employee credentials harvested by malware.
When a breach has already happened — the 72-hour clock, a tamper-evident record, and the coverage as it appears.
How it works →Plain-English narratives of how detected weaknesses could be exploited.
Verifies email authentication records to prevent spoofing.
Find out where a suspicious email really came from.
One-click remediation guidance for every finding.
Finds dangling DNS records attackers could claim.
Spots lookalike domains used for brand phishing.
Detects publicly accessible cloud storage buckets.
Validates certificates, ciphers, and encryption strength.
Checks that your web server sends all major browser security headers.
Checks the externally verifiable technical measures required under GDPR Article 32.
Card-payment posture, plus Californian privacy signals.
We name the corporate appliance instead of saying 'TLS error'.
Flags compromised credentials from known breach databases.
Export a shareable report for leadership or auditors.
Weekly or monthly full scans on Pro; daily security monitoring on MSP.
Included free — the verdict
Identifies domains that appear designed to imitate recognised organisations or trusted services.
Reviews whether the visible domain identity conflicts with common brand and service expectations.
Highlights domains that use character sets or encodings commonly abused in impersonation attacks.
Uses public registration context to help distinguish established services from newly created infrastructure.
Checks whether the domain resolves and whether the public technical setup is consistent with a legitimate service.
Reviews whether the domain presents a valid, current certificate for the service being checked.
Cross-references public abuse and malware intelligence to identify known harmful infrastructure.
Includes browser-level safety context where available.
Surfaces useful public ownership and registrar context where available.
Reviews visible page evidence for impersonation and credential-harvesting indicators.
Looks for technical patterns often associated with disposable or automated phishing infrastructure.
Adds hosting and network reputation context to help explain why a domain needs closer review.
Captures a safe view of the page and the resources it loads so teams can review evidence without clicking through themselves.
Submit one suspicious domain manually, or paste a forwarded email and review extracted candidate domains before queueing them into normal investigations.
Authenticated users get an assistant scoped to verdicts, intake, email parsing, bulk investigations, monitoring, reports, plan limits and safe next steps.
Paste up to 50 suspicious domains at once on Pro, or up to 250 domains per bulk list on MSP. Sortable verdict table, CSV export, deep-link into each individual investigation. Ideal for fraud triage and supplier vetting.
Generate a short-lived public link to a verdict. Send to a colleague or the person who reported the suspicious email — they see the outcome and practical evidence, no sign-in needed.
Monitor selected domains and receive an alert when the user-facing verdict changes materially.
One-click PDF export of the investigation outcome, findings, factual metadata and remediation context. Keep a record, share with stakeholders, attach to an incident ticket.
The verdict combines multiple evidence categories and presents the practical outcome. One Pro subscription unlocks Pro on both the authenticity app and the security app.
No installation, no agents, no access keys. Give us a domain or an email and we run the checks a careful person would — without you having to click anything.
A domain from an email, a text or a QR code — or the whole message. No password and no card; anything needing an account gets a secure sign-in link.
Non-intrusive external checks of public technical, reputation and authenticity evidence, run in parallel. Nothing is installed and nothing touches your systems.
A clear risk rating or verdict, the findings behind it in plain English, and the practical next step. Pro adds PDF reports you can share, and monitoring so you are told when it changes.
External DNS intelligence
Every scan builds a visual map of the domain's public DNS infrastructure — nameservers, mail servers, IP addresses, PTR records, and CT log subdomains — using only publicly available data.
Network Topology
DNS map for acmecorp.com — A, NS, MX, PTR and CT log subdomains only
Non-intrusive. Built exclusively from public DNS records, certificate transparency logs, and reverse-DNS lookups. All information shown is already accessible to anyone on the public internet.
Example findings
Every finding comes with a plain-English explanation of the risk and a specific action to fix it.
What this means
There is no DMARC record published for this domain. This means any attacker can send email that appears to come from the domain — staff, customers, and partners will see the brand in the From address with no way to distinguish it from a genuine message.
How to fix it
Publish a DMARC TXT record at _dmarc.yourdomain.com starting with p=quarantine to begin collecting reports. Once all legitimate senders are confirmed in SPF and DKIM, upgrade to p=reject to block spoofed email entirely.
What this means
Three sets of employee credentials associated with this domain have been identified in infostealer malware logs. These are active, real-world exposures — the affected accounts may already be accessible to threat actors.
How to fix it
Immediately reset passwords for affected accounts and revoke any active sessions. Enable MFA on all accounts if not already enforced. Notify affected employees and review access logs for signs of unauthorised access in the preceding 90 days.
What this means
A subdomain has a dangling CNAME record pointing to a cloud service (e.g. GitHub Pages, Heroku, Netlify) where the target resource no longer exists. An attacker can claim that resource and host arbitrary content — phishing pages, malware, or credential-harvesting forms — under the affected domain.
How to fix it
Remove the dangling CNAME record from your DNS immediately. If the subdomain is still needed, reclaim the corresponding resource in the cloud platform before re-publishing. Audit all subdomains regularly for stale records.
What this means
The TLS certificate for this domain expires in under a week. When it expires, all major browsers will display a full-page security warning to visitors, blocking access until the certificate is renewed. This affects both customer trust and any automated systems that validate certificates.
How to fix it
Renew the certificate immediately through your certificate authority or hosting provider. If using Let's Encrypt, check that the auto-renewal cron job or ACME client is running correctly — it should renew automatically at 30 days remaining.
What this means
Two typosquatted domains closely resembling this domain are registered and actively resolving — meaning they are live and potentially serving content. These are commonly used to conduct phishing campaigns against your customers and employees.
How to fix it
Monitor the identified lookalike domains via threat intelligence feeds. Where feasible, register the most likely typosquat variants defensively. If a lookalike is hosting phishing content, report it to the registrar and relevant abuse contacts for takedown.
Every scan generates a full remediation plan like this — specific to the domain under review, ready to share with your team or auditors.
Not sure where to start?
Every finding in your report has a Fix with Claude button. One click opens Claude.ai with the relevant domain details already filled in. Just hit send — Claude will tell you exactly what to change, in plain English, written for the detected setup.
Every finding also links to a written guide with the exact DNS record or config value to add, instructions for the most common platforms, and how to verify the fix worked. No jargon.
Pricing
Start free. Upgrade when your external domain risk monitoring needs scheduled checks, richer evidence, portfolio workflow, or client-ready reporting.
One account, both apps — one subscription. Free, Pro or MSP, a single MyDomainRisk sign-in unlocks both apps — the security app (monitor the external risk around any domain you assess) and the authenticity app (check whether a suspicious link or supplier domain is genuine). Same non-intrusive checks underneath, different lens depending on the question you're asking. One tier, one subscription, both tools.
For checking any domain
Free
No credit card required. Start scanning immediately.
For IT teams and consultants monitoring multiple domains
Pro
Everything you need to monitor a full domain portfolio.
50 tracked domains · 50 shared daily checks · 50 history per security domain
Managing multiple separate customer estates?See MSP →
No lock-in. Cancel any time, or downgrade at the end of the period and keep Pro until the billing date.
For consultancies, MSPs and agencies managing many client estates
MSP
Everything in Pro, plus daily security monitoring with immediate deeper refreshes when material changes appear, Portfolio clients, branded report bundles and evidence packs with report checks, delegated read-only portal access, a client audit trail, per-client Priorities work queues and Alerts, and progress signals for client reviews.
Need more than 250 domains? support@mydomainrisk.com
No lock-in. Cancel any time, or downgrade to Pro / Free at period end.
Do I need a credit card to try it?
No. The Free plan requires only your email address — no payment details at any point.
Will this affect my website or cause any disruption?
No. Every check is external and non-intrusive. Most read public records — DNS, certificates, registration data, threat-intelligence feeds. A few look at your site exactly the way a visitor's browser would: a TLS handshake and a single ordinary page request. Your logs would show the equivalent of one normal page visit; nothing is probed, logged into, or changed. The full contract is on our How we scan page.
How is this different from the free NCSC checks?
Use both. The NCSC's free Check Your Cyber Security tools are excellent for a one-off government-backed snapshot of email security and browser safety. MyDomainRisk covers a much wider set of external checks, keeps watching on a schedule, tracks your score over time, and turns every finding into a prioritised, plain-English fix path — the day-two-onwards work the snapshot can't do.
How does MSP daily monitoring work?
Pro schedules run full scans weekly or monthly. MSP also checks current security signals each day, carries forward slower-moving evidence from the latest full refresh, and immediately runs a deeper refresh when a material change appears.
Can I cancel my Pro or MSP subscription at any time?
Yes. You can downgrade or cancel from your account page at any time. No contracts, no minimum term — you keep your paid features until the end of the current billing period.
What happens to my data after a scan?
Scan results are stored against your account in line with your plan limits. You can export or delete your data at any time. See our Privacy Policy for full details.
Free for up to 5 domains. No card required. Pro unlocks bulk scanning, weekly or monthly full scans, and full breach reports; MSP adds daily security monitoring.
Full domain scan — free, 60 seconds