Non-intrusive external scanning

DMARC, SPF and DKIM check — in seconds, for free.

MyDomainRisk inspects email authentication end-to-end: DMARC record and policy (none / quarantine / reject), SPF record plus the lookup count, DKIM selectors, and MTA-STS. It tells you whether a domain can be spoofed today — and exactly which record needs changing to lock it down. No signup.

No password. No credit card. Just your email to receive results.

One sign-in, both apps — Free, Pro or MSP covers security and authenticity. No second subscription.

Hosted on security-certified infrastructure providers.

acmecorp.com

Security posture: critical

34

/ 100

TLS / Certificate
18/30
Security headers
9/30
DNS / Email
7/20
Internet exposure
10/20

CRITICAL FINDINGS

!

Domain can be impersonated to send phishing email — no DMARC enforcement

Critical
!

3 employee credentials found in stealer logs — active breach risk

Critical
!

Subdomain hijacking vulnerability — attacker can host content on affected domain

High
!

TLS certificate expires in 6 days — site will show browser security warnings

High
!

2 lookalike domains actively resolving — phishing infrastructure detected

High
Scan a domain free — 60 seconds →

No password · No credit card · Just your email

50+

Security checks

< 60s

Scan time

Clear

Risk rating

40+

Intel sources

Sample Intelligence Providers

Google Web RiskHave I Been PwnedShodanurlscan.ioAbuseIPDBHudsonRock

MyDomainRisk combines signals from trusted sources including Google Web Risk, Have I Been Pwned, Shodan, urlscan.io, AbuseIPDB, and HudsonRock, alongside public DNS, certificate transparency, phishing, malware, and ransomware intelligence feeds.

Evidence Signals Checked

Malware and phishing reputationBreach exposureInternet exposureBrand-abuse indicatorsRansomware leak monitoring

One subscription, every lens. Cyber Essentials · GDPR · PCI · CCPA · DMARC · Suppliers · Invoice · Crypto · MSP. See them all ↓

Everything domain security needs

A comprehensive scan covering all the externally observable security signals that matter — with no special access or agent required.

Included free

Free

Infostealer Exposure

Detects employee credentials harvested by malware.

Free

Attack Scenarios

Plain-English narratives of how detected weaknesses could be exploited.

Free

DNS Security

Verifies email authentication records to prevent spoofing.

Free

Fix It with Claude

One-click remediation guidance for every finding.

Free

Subdomain Takeover Detection

Finds dangling DNS records attackers could claim.

Free

Domain Exposure

Spots lookalike domains used for brand phishing.

Free

Cloud Storage Exposure

Detects publicly accessible cloud storage buckets.

Free

TLS & SSL Analysis

Validates certificates, ciphers, and encryption strength.

Free

Security Headers

Checks that your web server sends all major browser security headers.

Free

GDPR Technical Baseline

Checks the externally verifiable technical measures required under GDPR Article 32.

Free

US Compliance — PCI DSS + CCPA

Advisory technical checks for the US market.

Free

TLS-inspection transparency

We name the corporate appliance instead of saying 'TLS error'.

Pro features
Pro

Data Breach Detection

Flags compromised credentials from known breach databases.

Pro

PDF Security Reports

Export a shareable report for leadership or auditors.

Pro

Scheduled Monitoring

Automated weekly or monthly scans on Pro; daily schedules on MSP.

Up and running in three steps

No installation. No agents. No access keys.

1

Enter your email

No password, no credit card. We send you a secure sign-in link — click it and you're in.

2

We run the checks

MyDomainRisk performs 50+ non-intrusive security checks — TLS, headers, DNS, network infrastructure, threat intelligence, breaches, exposure — in under a minute.

3

Get your risk report

Review the risk rating, prioritised findings and supporting evidence in the dashboard. Pro users can download a PDF report to share with leadership or auditors.

Pricing

Simple, transparent pricing

Start free. Upgrade when you need monitoring, richer evidence, portfolio workflow, or client-ready reporting.

One account, both apps — one subscription. Free, Pro or MSP, a single MyDomainRisk sign-in unlocks both apps — the security app (harden the external configuration of any domain you want to assess) and the authenticity app (check whether a suspicious link or supplier domain is genuine). Same non-intrusive checks underneath, different lens depending on the question you're asking. One tier, one subscription, both tools.

For checking any domain

Free

£0/month

No credit card required. Start scanning immediately.

Full domain scan — free, 60 seconds
  • Useful starter posture checks for up to 5 domains
  • Risk rating with prioritised findings and plain-English fixes
  • Core TLS, headers, DNS/email, exposure and browser-safety checks
  • Attack Scenarios, topology view and recent-change context
  • 5 security scans per day with short history

For IT teams and consultants monitoring multiple domains

Pro

£19/month

Everything you need to monitor a full domain portfolio.

Upgrade to Pro
  • Everything in Free, expanded to 50 security domains and 50 authenticity domains
  • Scheduled monitoring, bulk scans, PDF reports and longer history
  • Portfolio cockpit with progress movement, read-only Assets, Priorities and Alerts
  • Richer evidence: breach/infostealer exposure, page analysis, IP reputation and full compliance detail
  • Verified-owner eligibility with consent-gated deeper-mode runs for verified domains

50 security domains · 50 scans per day · 50 history per domain

Managing multiple separate customer estates?See MSP →

No lock-in. Cancel any time, or downgrade at the end of the period and keep Pro until the billing date.

For service providers

For consultancies, MSPs and agencies managing many client estates

MSP

£99/month

Everything in Pro, plus Portfolio clients, branded report bundles with report checks, delegated read-only portal access, a client audit trail, per-client Priorities work queues and Alerts, and progress signals for client reviews.

Upgrade to MSP
  • Everything in Pro, scaled for multi-customer operations
  • Portfolio clients with per-client schedules, Priorities, Alerts and CSV exports
  • Client-ready report bundles with report checks, branding, Prepared by / Prepared for and progress narratives
  • Delegated read-only client portal plus client audit trail
  • Higher capacity: 250 security domains/scans per day and 150 authenticity domains/investigations per day

Need more than 250 security or 150 authenticity domains? support@mydomainrisk.com

No lock-in. Cancel any time, or downgrade to Pro / Free at period end.

Frequently asked questions

Do I need a credit card to try it?

No. The Free plan requires only your email address — no payment details at any point.

Will this affect my website or cause any disruption?

No. Every check is a passive, external observation — we query publicly available data and DNS records only. Nothing is sent to your server and nothing is changed.

Can I cancel my Pro subscription at any time?

Yes. You can downgrade to Free or cancel immediately from your account page. No contracts, no minimum term.

What happens to my data after a scan?

Scan results are stored against your account in line with your plan limits. You can export or delete your data at any time. See our Privacy Policy for full details.

Ready to check a domain?

Free for up to 5 domains. No card required. Pro plans unlock bulk scanning, scheduled monitoring, and full breach reports.

Full domain scan — free, 60 seconds