Bounded requests
Collection limits constrain each check. Repeated or concurrent scans still generate traffic, including across domains that share infrastructure.
Non-intrusive external scanning
We observe; we don't touch
Trusting a security tool means knowing exactly what it does — and what it will never do. This page is that contract, in plain English.
The short version.
Every check looks only at what a domain already shows the public internet. Nothing is installed, nothing is logged into, nothing is attacked. That is why a check needs no access, no agreement and no agent: it reads what is already published, causes no disruption, and changes nothing.
One rule decides what is in a scan and what is not.
Every MyDomainRisk check is a non-intrusive external observation. We look at what a domain already shows to the public internet — its DNS records, its certificates, the headers its website sends, what public threat-intelligence sources say about it. Website protocol checks complete a small, bounded set of TLS handshakes without sending application data. They do not enumerate ciphers or attempt exploitation. Collection records for DNSSEC, disclosure files and cloud storage distinguish completed, incomplete and unavailable checks; completed collection is not a security pass. Historical reports retain their original evidence. RPKI routing intelligence is currently unavailable. Published vulnerability intelligence adds context without sending additional probes to the target.
The question every MSP and multi-domain owner asks before turning on scheduled monitoring.
Collection limits constrain each check. Repeated or concurrent scans still generate traffic, including across domains that share infrastructure.
The scan description explains the checks we perform; it is not a blanket assurance about permission or a target system's response.
We do not attempt exploitation, credential testing or intentional modification of target systems.
A weekly scan puts no more load on any one domain than a search engine visiting the homepage.
Eight categories of publicly visible signal. All of it is information the domain already publishes.
Pro/MSP full scans sample up to six advertised nameservers and two parent servers, plus up to five mail servers at one public address each. Dated evidence cards show DNS responses, mail TLS and supported authenticated DANE certificate bindings. Missing responses remain unverified. Matching responses do not prove independent infrastructure or continuous availability. No email is sent; Free scans and daily monitoring skip these advisories.
Certificate validity and expiry, plus bounded TLS 1.0–1.3 handshakes on website port 443 on every plan. Unavailable probes remain unverified; this does not enumerate ciphers or certify the configuration.
Published email records, observed DKIM key structure, and MTA-STS policy syntax and mail-server matching. DNSSEC validation is reported separately from signing-record presence. Unavailable evidence remains unverified; these checks do not test actual message authentication.
The protective HTTP headers your site sends with every page.
Published service and vulnerability observations, supplemented by bounded connection checks. Dated known-exploitation intelligence helps prioritise reported vulnerabilities without claiming compromise or changing the domain score. Where observed versions match the limited lifecycle coverage, reports show dated upstream support context. Distribution backports, extended vendor support and installed patch status remain unverified. This adds no target requests.
Pro/MSP Network Map includes a mobile-friendly list and expandable map of observed website, email and DNS IP locations, with lookup dates, country borders and zoom/pan controls. Locations are approximate: CDN, proxy and anycast addresses may represent an edge, not the origin. Physical server locations and data residency remain unverified. Missing locations stay unknown. This adds no target requests and does not change the security score.
Registration expiry, transfer locks and DNS configuration. Pro/MSP full scans automatically review up to 50 related hosts per scanned domain using public certificate records and bounded DNS/HTTPS checks. Daily monitoring skips that review. Discovery is incomplete and indicators need ownership review; they do not confirm takeover or change the main score.
Registered domains that imitate yours — the raw material of phishing against your customers and staff.
Whether your domain, infrastructure, or employee credentials appear in trusted public and commercial threat feeds.
The externally verifiable subset of GDPR Article 32, PCI DSS, and related baselines — formatted as evidence for auditors.
We compare the scan's externally visible checks with current guidance and transparent security benchmarks. A good result is useful evidence that your public domain follows many of the same technical expectations; it is not certification, a compliance decision or a replacement for internal testing.
Comparative analysis last reviewed: 17 August 2026
Close means broad coverage of the same external surface. Strong overlap means many shared checks within a narrower specialist benchmark. Supporting evidence means selected requirements only, and Limited means only a small externally visible part of a much broader framework.
This list is a commitment, not a description of current limitations.
Anything deeper — and there's very little we'd ever add — would be separate, clearly labelled, opt-in, and gated behind verified proof that you own the domain. It would never be quietly added to the standard scan.
Every request identifies itself as MyDomainRisk-Scanner and is cryptographically signed, so a site operator can verify it really came from us. About our scanner has the exact user agent, what it fetches, and how to block it.
External observation cannot see everything, and we would rather say so.
We don't assess your internal network, your endpoints, your staff practices, or anything behind a login. A scan is one view of your risk, best used alongside internal reviews and penetration testing.
That nothing malicious was visible to our checks at the time of the scan. No verdict from any tool, ours included, is a guarantee. Use results to inform judgement, not to replace it.
MyDomainRisk is built and operated by Huro Data Technologies Ltd., a UK company — self-sustaining on subscriptions, not venture-funded, with no advertising, no data sales, and no resale of your information. Data handling is documented in our privacy policy and GDPR commitment; security researchers can find our vulnerability disclosure policy here.
The checker on our homepage runs genuine checks with no account, and shows exactly the kind of findings a full scan produces. Or browse a sample report first to see how a full scan reads.