Understand your domain risks.

Check your domain, understand the priorities, and share clear evidence. Security and authenticity tools for organisations and their advisers.

How well is this domain defended? — 50+ external checks

No password. No credit card. Just your email to receive results.

One sign-in, both apps — Free, Pro or MSP covers security and authenticity. No second subscription.

Hosted on security-certified infrastructure providers.

50+

Security checks

Ongoing

Monitoring available

Clear

Risk rating

Sample Intelligence Providers

Google Web RiskHave I Been PwnedShodanHudsonRock

MyDomainRisk combines browser safety reputation from Google Web Risk, breach exposure data from Have I Been Pwned, internet exposure data from Shodan and infostealer exposure intelligence from HudsonRock, alongside IP reputation, page threat analysis, public DNS, certificate transparency, phishing, malware and ransomware intelligence feeds.

Surface Compliance

Every scan includes advisory compliance cards alongside the main risk rating — externally visible evidence only, not a certification audit.

GDPR Technical BaselineFree + Pro

UK & EU — Article 32 technical advisory. ⓘ What's checked?

  • HTTPS redirect enforcedArt. 32(1)(a)Free
  • Privacy policy accessibleArt. 13 / 14Free
  • Cookie consent mechanismePrivacy / Art. 7Free
  • No mixed contentArt. 32(1)(a)Pro
  • Vulnerability disclosure policyArt. 32(1)(d)Pro
  • Third-party tracker enumerationArt. 28 / Art. 13Pro

Advisory only. A passing score does not constitute GDPR compliance — organisational measures, DPAs, and data retention policies are out of scope.

PCI DSS SurfaceFree + Pro

PCI DSS 4.0 advisory review — applies wherever card payments are taken. ⓘ What's checked?

PCI DSS 4.0 Surface

  • •HTTPS enforcement
  • •TLS protocol health
  • •Certificate validity
  • •HSTS presence
  • •Known vulnerability exposure (severity scores on Pro)
  • •Heartbleed exposure (Pro)
  • •Exposed database services
  • •Public cloud bucket exposure
  • •Mail transport security
  • •security.txt disclosure policy

Advisory only. Not a PCI DSS certification — formal audits, cardholder-data-environment scoping, and organisational controls remain out of scope.

US Privacy — CCPA / CPRAFree + Pro

California privacy advisory review — relevant if you serve California residents. ⓘ What's checked?

US Privacy — CCPA / CPRA

  • •HTTPS enforcement
  • •Privacy policy presence
  • •'Do Not Sell or Share' opt-out mechanism
  • •Cookie consent / CMP
  • •Global Privacy Control support

Advisory only. Not a legal CCPA compliance assessment — organisational controls and legal obligations remain out of scope.

From findings to action and evidence

Keep the priorities, the work and the next client conversation together. Portfolio workspaces are included on Pro and MSP.

  1. Add your domains

    Import a list into a client workspace and record business criticality to put findings in context.

  2. Review the priorities

    Start with serious findings and practical next steps. Evidence dates and collection gaps stay visible.

  3. Track what changed

    Review first-observed and last-confirmed dates. Comparable retained evidence is needed before a repair is verified.

  4. Share a clear report

    Use PDF reports on Pro; MSP adds branded client bundles, board analysis and a delegated read-only portal.

Help inside the app

Built-in AI help is available on every plan, within usage limits, for product questions. Fix with Claude is a separate option for supported findings.

Email evidence beyond DNS

Pro and MSP can upload DMARC XML and SMTP TLS JSON aggregate reports in Portfolio Email health. Review observed mail evidence alongside published policy; raw uploads are discarded.

Evidence for GRC reviews

Pro and MSP export external evidence as JSON and a matching PDF with a content hash. Pass, fail and unverified remain distinct. Use it for GRC intake; it is not a compliance certificate or a native GRC integration.

Everything both apps check

Externally observable signals for both lenses — how well a domain is defended, and whether a domain is what it claims to be. Nothing installed.

Domain security

Included free

Free

Infostealer Exposure

Detects employee credentials harvested by malware.

Free

Incident Watch

When a breach has already happened — the 72-hour clock, a tamper-evident record, and the coverage as it appears.

How it works →
Free

Attack Scenarios

Plain-English narratives of how detected weaknesses could be exploited.

Free

DNS Security

Verifies email authentication records to prevent spoofing.

Free

Email forensics

Find out where a suspicious email really came from.

Free

Fix It with Claude

Practical remediation guidance for supported findings.

Free

Subdomain Takeover Detection

Finds dangling DNS records attackers could claim.

Free

Domain Exposure

Spots lookalike domains used for brand phishing.

Free

Cloud Storage Exposure

Reviews matching storage names; ownership remains unverified.

Free

TLS & SSL Analysis

Checks certificates and website TLS protocol support.

Free

Security Headers

Checks that your web server sends all major browser security headers.

Free

GDPR Technical Baseline

Checks the externally verifiable technical measures required under GDPR Article 32.

Free

PCI DSS Surface + US Privacy

Card-payment posture, plus Californian privacy signals.

Free

TLS-inspection transparency

We name the corporate appliance instead of saying 'TLS error'.

Pro features
Pro

Data Breach Detection

Flags compromised credentials from known breach databases.

Pro

PDF Security Reports

Export a shareable report for leadership or auditors.

Pro

Scheduled Monitoring

A weekly watch on every plan. Pro adds monthly and Pro capacity; MSP adds daily security monitoring.

Domain authenticity

Included free — the verdict

Free

Lookalike patterns

Identifies domains that appear designed to imitate recognised organisations or trusted services.

Free

Brand similarity

Reviews whether the visible domain identity conflicts with common brand and service expectations.

Free

Internationalised domains

Highlights domains that use character sets or encodings commonly abused in impersonation attacks.

Free

Domain history

Uses public registration context to help distinguish established services from newly created infrastructure.

Free

DNS and reachability

Checks whether the domain resolves and whether the public technical setup is consistent with a legitimate service.

Free

TLS health

Reviews whether the domain presents a valid, current certificate for the service being checked.

Free

Threat intelligence

Cross-references public abuse and malware intelligence to identify known harmful infrastructure.

Free

Browser safety context

Includes browser-level safety context where available.

Free

Registration metadata

Surfaces useful public ownership and registrar context where available.

Free

Page review

Reviews visible page evidence for impersonation and credential-harvesting indicators.

Free

Infrastructure patterns

Looks for technical patterns often associated with disposable or automated phishing infrastructure.

Pro features
Pro

Hosting reputation

Adds hosting and network reputation context to help explain why a domain needs closer review.

Pro

Page screenshot + resource summary

Captures a safe view of the page and the resources it loads so teams can review evidence without clicking through themselves.

Pro

Intake queue + email parser

Submit one suspicious domain manually, or paste a forwarded email and review extracted candidate domains before queueing them into normal investigations.

Pro

Authenticity AI assistant

Authenticated users can ask about anything visibly presented in MyDomainRisk. Answers are tailored to their plan, remain product-only, and do not disclose scan/scoring methodology, reverse-engineering detail or unlisted data sources.

Pro

Bulk investigate

Paste up to 50 suspicious domains at once on Pro, or up to 250 domains per bulk list on MSP. Sortable verdict table, CSV export, deep-link into each individual investigation. Ideal for fraud triage and supplier vetting.

Pro

Shareable verdict reports

Generate a short-lived public link to a verdict. Send to a colleague or the person who reported the suspicious email — they see the outcome and practical evidence, no sign-in needed.

Pro

Verdict-change alerts

Monitor selected domains and receive an alert when the user-facing verdict changes materially.

Pro

PDF investigation report

One-click PDF export of the investigation outcome, findings, factual metadata and remediation context. Keep a record, share with stakeholders, attach to an incident ticket.

The verdict combines multiple evidence categories and presents the practical outcome. One Pro subscription unlocks Pro on both the authenticity app and the security app.

Three steps, whichever check you need

Start with a domain or a suspicious message. No software installation is needed. Full scan time varies; some supporting checks are added later with their own dates.

1

Tell us what to look at

A domain from an email, a text or a QR code — or the whole message. No password and no card; anything needing an account gets a secure sign-in link.

2

We run the checks

Our scans use bounded, external, non-intrusive checks. They do not attempt exploitation, credential testing or intentional modification of target systems.

3

Get the answer

A clear risk rating or verdict, the findings behind it in plain English, and the practical next step. Free includes weekly security monitoring. Pro adds PDF reports and weekly or monthly full scans; MSP adds daily security monitoring.

External DNS intelligence

See the domain's network topology

Every scan builds a visual map of the domain's public DNS infrastructure — nameservers, mail servers, IP addresses, PTR records, and CT log subdomains — using only publicly available data.

Network Topology

DNS map for acmecorp.com — A, NS, MX, PTR and CT log subdomains only

Live feature

Non-intrusive. Built exclusively from public DNS records, certificate transparency logs, and reverse-DNS lookups. All information shown is already accessible to anyone on the public internet.

Root domain
IP / A record
Nameserver
Mail server (MX)
CT log subdomain
Dangling CNAME (hijackable)
Click to expand
acmecorp.comRoot domain104.26.10.45A recordCloudflare, Inc.ns1.cloudflare.comNS record · 162.159.0.31Cloudflare, Inc.ns2.cloudflare.comNS record · 162.159.1.31Cloudflare, Inc.smtp.office365.comMX record (pri 0)40.107.4.2Microsoft 365www.acmecorp.comCT log subdomain · Cloudflarestaging.acmecorp.com⚠ Dangling CNAME → Heroku
Nodes are draggable and zoomable in the app · Data sourced from public DNS queries only← scroll →

Example findings

Remediation actions for acmecorp.com

Every finding comes with a plain-English explanation of the risk and a specific action to fix it.

No DMARC enforcement — domain can be spoofed
Critical

What this means

There is no DMARC record published for this domain. This means any attacker can send email that appears to come from the domain — staff, customers, and partners will see the brand in the From address with no way to distinguish it from a genuine message.

How to fix it

Publish a DMARC TXT record at _dmarc.yourdomain.com with an aggregate-report address. Review which legitimate senders pass aligned SPF or DKIM, then move towards p=reject when those sources are ready.

Employee credentials found in stealer logs
Critical

What this means

Three sets of employee credentials associated with this domain have been identified in infostealer malware logs. These are active, real-world exposures — the affected accounts may already be accessible to threat actors.

How to fix it

Immediately reset passwords for affected accounts and revoke any active sessions. Enable MFA on all accounts if not already enforced. Notify affected employees and review access logs for signs of unauthorised access in the preceding 90 days.

Subdomain hijacking vulnerability detected
High

What this means

A subdomain has a dangling CNAME record pointing to a cloud service (e.g. GitHub Pages, Heroku, Netlify) where the target resource no longer exists. An attacker can claim that resource and host arbitrary content — phishing pages, malware, or credential-harvesting forms — under the affected domain.

How to fix it

Remove the dangling CNAME record from your DNS immediately. If the subdomain is still needed, reclaim the corresponding resource in the cloud platform before re-publishing. Audit all subdomains regularly for stale records.

TLS certificate expires in 6 days
High

What this means

The TLS certificate for this domain expires in under a week. When it expires, all major browsers will display a full-page security warning to visitors, blocking access until the certificate is renewed. This affects both customer trust and any automated systems that validate certificates.

How to fix it

Renew the certificate immediately through your certificate authority or hosting provider. If using Let's Encrypt, check that the auto-renewal cron job or ACME client is running correctly — it should renew automatically at 30 days remaining.

Lookalike domains actively resolving
High

What this means

Two typosquatted domains closely resembling this domain are registered and actively resolving — meaning they are live and potentially serving content. These are commonly used to conduct phishing campaigns against your customers and employees.

How to fix it

Monitor the identified lookalike domains via threat intelligence feeds. Where feasible, register the most likely typosquat variants defensively. If a lookalike is hosting phishing content, report it to the registrar and relevant abuse contacts for takedown.

Every scan generates a full remediation plan like this — specific to the domain under review, ready to share with your team or auditors.

Not sure where to start?

Fix It with Claude

Supported findings have a Fix with Claude button. It opens Claude.ai with relevant domain details ready for you to review and send. Check any suggested configuration against your environment before applying it.

Step-by-step guides

Selected findings link to a written guide with example DNS records or configuration, instructions for common platforms, and ways to verify the change. Findings that need more evidence remain a verification task.

Pricing

Simple, transparent pricing

Start free. Upgrade when you need richer evidence, portfolio workflow, client-ready reporting, or more frequent and higher-capacity schedules.

One account, both apps — one subscription. Free, Pro or MSP, a single MyDomainRisk sign-in unlocks both apps — the security app (how well a domain is defended) and the authenticity app (whether a domain is what it claims to be). Same non-intrusive checks underneath, different lens depending on the question you're asking. One tier, one subscription, both tools.

Compare plans at a glance

Monthly price

Free

Free

Pro

£19

MSP

£99

Tracked domains in each app

Free

5

Pro

50

MSP

250

Daily checks shared across both apps

Free

5

Pro

50

MSP

250

Security monitoring

Free

Weekly watch

Pro

Weekly or monthly full scans

MSP

Daily monitoring; weekly or monthly full scans

Portfolio client workspaces

Free

Not included

Pro

Included

MSP

Included

PDF reports and GRC evidence export

Free

Not included

Pro

Included

MSP

Included

Branded client bundles and delegated portal

Free

Not included

Pro

Not included

MSP

Included

Built-in AI help and account API

Free

Included, within limits

Pro

Included, within limits

MSP

Included, within limits

Imports use your tracked-domain allowance; they do not add extra capacity. Public anonymous checks have separate usage limits.

For checking how well a domain is defended

Free

£0/month

No credit card required. Start scanning immediately.

Start a full scan — free
  • Useful starter posture checks for up to 5 domains
  • Risk rating with prioritised findings and plain-English fixes
  • Core TLS, headers, DNS/email, exposure and browser-safety checks
  • Attack Scenarios, topology view and recent-change context
  • 5 daily checks shared across scans, investigations and signed-in email checks, with short history
  • Weekly security watch on domains you track — put a domain on a weekly schedule without upgrading
  • Incident Watch — run one live breach incident at a time, with a 72-hour ICO clock and a tamper-evident record
  • API access from your own apps and scripts, at your plan's limits

For IT teams and consultants monitoring multiple domains

Pro

£19/month

Everything you need to monitor a full domain portfolio.

Upgrade to Pro
  • Everything in Free, expanded to 50 tracked domains in each app and 50 daily checks shared across both apps
  • Weekly or monthly full scans at Pro capacity, bulk scans, PDF reports and longer history
  • External evidence export (Security) — continuous outside-in evidence for GRC tools; complements GRC, doesn’t replace it.
  • Portfolio client workspaces with paste/CSV imports up to 50 domains, evidence coverage, comparable trends and observed shared dependencies
  • Portfolio cockpit with progress movement, customer-confirmed service roles and business criticality, read-only Assets, Priorities, Alerts and an Email health roll-up
  • Richer evidence: breach/infostealer exposure, page analysis, IP abuse reputation and full compliance detail
  • Verified-owner eligibility with consent-gated deeper-mode runs for verified domains
  • API access with Pro limits — 50 tracked domains and 50 daily checks through the same key
  • Incident Watch — up to 5 breach incidents open at once
  • Incident Watch briefing — a plain-English account written from your incident record: the parties and their roles, what changed, the decision in front of you and what to ask the supplier. Versioned, downloads as a PDF, and opt-in per incident

50 tracked domains · 50 shared daily checks · 50 history per security domain

Managing multiple separate customer estates?See MSP →

No lock-in. Cancel any time, or downgrade at the end of the period and keep Pro until the billing date.

For service providers

For consultancies, MSPs and agencies managing many client estates

MSP

£99/month

Everything in Pro, with Portfolio client imports raised from 50 to 250 domains, plus daily security monitoring with immediate deeper refreshes when material changes appear, branded report bundles and evidence packs with report checks, delegated read-only portal access, a client audit trail, per-client Priorities work queues and Alerts, and progress signals for client reviews.

Upgrade to MSP
  • Everything in Pro, scaled for multi-customer operations
  • Daily security monitoring with an immediate deeper refresh when a material change appears
  • External evidence export (Security) — continuous outside-in evidence for GRC tools; complements GRC, doesn’t replace it.
  • Portfolio client imports up to 250 domains, with per-client schedules, Priorities, Alerts and CSV exports
  • Client-ready report bundles and evidence packs with report checks, branding, Prepared by / Prepared for and progress narratives
  • Delegated read-only client portal plus client audit trail
  • Incident Watch — up to 25 breach incidents open at once, for handling several clients at the same time
  • Incident Watch briefing on every incident you run, so each client gets the same written account of where their breach stands
  • Higher capacity: 250 tracked domains in each app and 250 daily checks shared across scans, investigations and signed-in email checks

Need more than 250 domains? support@mydomainrisk.com

No lock-in. Cancel any time, or downgrade to Pro / Free at period end.

Frequently asked questions

Do I need a credit card to try it?

No. The Free plan requires only your email address — no payment details at any point.

Will this affect my website or cause any disruption?

Our scans use bounded, external, non-intrusive checks. They do not attempt exploitation, credential testing or intentional modification of target systems. This is not equivalent to a casual browser visit. See How we scan for the scope and limits.

How is this different from the free NCSC checks?

Use both. The NCSC's free Check Your Cyber Security tools are excellent for a one-off government-backed snapshot of email security and browser safety. MyDomainRisk covers a much wider set of external checks, keeps watching on a schedule, tracks your score over time, and presents findings with priorities and practical next steps — the day-two-onwards work the snapshot can't do.

How does MSP daily monitoring work?

Every plan can put a domain on a weekly watch, including Free. Pro schedules run full scans weekly or monthly at Pro capacity. MSP also checks current security signals each day, carries forward slower-moving evidence from the latest full refresh, and immediately runs a deeper refresh when a material change appears.

Can I cancel my Pro or MSP subscription at any time?

Yes. You can downgrade or cancel from your account page at any time. No contracts, no minimum term — you keep your paid features until the end of the current billing period.

What happens to my data after a scan?

Scan results are stored against your account in line with your plan limits. You can export or delete your data at any time. See our Privacy Policy for full details.

Where is my data stored?

In the United States. Your account and scan history are stored in a database hosted by Render in Oregon, with weekly backups kept in the US for up to 12 months. A scan that cannot complete from Oregon may be retried once from Frankfurt, Germany, without storing data there. UK or EEA storage is not currently offered. See our Privacy Policy for the legal basis of each transfer.

Ready to check a domain?

Free for up to 5 domains, including a weekly security watch. No card required. Pro unlocks bulk scanning, PDF reports, portfolio workflow and monthly or Pro-capacity full scans; MSP adds daily security monitoring.

Start a full scan — free