# MyDomainRisk > External domain risk monitoring and suspicious-domain checks for SMEs, consultants and MSPs. > MyDomainRisk uses non-intrusive external checks of public security and authenticity signals, then turns findings into plain-English fixes and client-ready evidence. ## Best starting points - [Homepage](https://mydomainrisk.com/) - Product overview and free security/authenticity checks. - [Agent access](https://mydomainrisk.com/agents) - Machine-usable capabilities, API operations, response meanings and safety boundaries. - [OpenAPI](https://mydomainrisk.com/openapi.json) - OpenAPI 3.1 specification for the restricted external developer API. - [How we scan](https://mydomainrisk.com/how-we-scan) - The non-intrusive external scanning contract and what MyDomainRisk will not do. - [Free NCSC checks](https://mydomainrisk.com/ncsc-checks) - How MyDomainRisk complements official UK NCSC free tools. - [Check a message](https://mydomainrisk.com/check-a-message) - Public suspicious-message checker. - [Check an email](https://mydomainrisk.com/email-check) - Public email provenance check; analysed in memory and discarded. - [Supplier audit](https://mydomainrisk.com/supplier-audit) - External domain risk checks for third-party suppliers. - [MSP client reporting](https://mydomainrisk.com/msp) - Multi-client monitoring and report workflows for MSPs. - [Sample security report](https://security.mydomainrisk.com/sample-report) - Public sample of the security reporting experience. - [Sample MSP client report](https://security.mydomainrisk.com/sample-client-report) - Public sample of a client-ready report bundle. ## When a breach or incident has already happened - [Data breach response playbook](https://mydomainrisk.com/breach-playbook) - UK-focused checklist for the first hour and first 72 hours: containment, preserving evidence, questions to put to a breached supplier, and the UK reporting decision. Links to current ICO and NCSC guidance. General operational guidance, not legal, regulatory, insurance or forensic advice. - [Run a breach incident](https://mydomainrisk.com/incident-watch) - Incident Watch: a 72-hour ICO countdown from the date you record becoming aware, a tamper-evident incident record where entries are chained so a later change to an earlier one can be detected, and public coverage collected per organisation. Available on every plan including Free. - [Suspicious-domain response](https://mydomainrisk.com/suspicious-domain-response) - From "is this real?" to a credible takedown request when a lookalike domain is impersonating you. - [Invoice / BEC check](https://mydomainrisk.com/invoice-check) - Payment-diversion and business-email-compromise checks on a suspicious invoice or payment-detail change. ## Fix-it guides Step-by-step remediation for the findings a domain security scan reports. Each guide explains what the finding means, why it matters, and the exact record or header to publish. - [How to Fix Your SPF Record](https://mydomainrisk.com/guides/fix-spf-record) - Missing, too-permissive, or misconfigured SPF, including the 10 DNS lookup limit. - [How to Fix a Weak DMARC Policy](https://mydomainrisk.com/guides/fix-dmarc-policy) - Moving from p=none or p=quarantine to enforcement without breaking legitimate mail. - [How to Set Up DKIM](https://mydomainrisk.com/guides/fix-dkim-not-configured) - Cryptographic email signing, including Microsoft 365 and Google Workspace. - [How to Configure MTA-STS](https://mydomainrisk.com/guides/fix-mta-sts-not-configured) - Enforcing TLS encryption for inbound mail. - [How to Enable DNSSEC](https://mydomainrisk.com/guides/fix-dnssec-not-enabled) - Cryptographically signing DNS responses. - [How to Add CAA Records](https://mydomainrisk.com/guides/fix-caa-records-missing) - Restricting which certificate authorities may issue for your domain. - [How to Add HSTS to Your Website](https://mydomainrisk.com/guides/fix-hsts-not-configured) - Forcing browsers to always use HTTPS. - [How to Fix Your Content Security Policy](https://mydomainrisk.com/guides/fix-content-security-policy) - Missing or unsafe CSP. - [How to Add Missing Security Headers](https://mydomainrisk.com/guides/fix-missing-security-headers) - X-Content-Type-Options, X-Frame-Options and the rest. - [How to Create a security.txt File](https://mydomainrisk.com/guides/fix-security-txt-missing) - Publishing a route for security researchers to report a problem. - [What Is Subdomain Takeover?](https://mydomainrisk.com/guides/what-is-subdomain-takeover) - How dangling CNAME records let an attacker claim a subdomain. - [All guides](https://mydomainrisk.com/guides) - Index of the above. ## Compliance and audit use cases - [UK Cyber Essentials](https://mydomainrisk.com/cyber-essentials) - Pre-assessment readiness against the externally visible controls. - [GDPR Article 32](https://mydomainrisk.com/gdpr-scan) - UK and EU technical baseline. - [PCI DSS surface](https://mydomainrisk.com/pci-dss-scan) - External attack-surface review. - [CCPA / CPRA](https://mydomainrisk.com/ccpa-compliance-check) - US privacy baseline. - [DMARC / SPF / DKIM audit](https://mydomainrisk.com/dmarc-check) - Email authentication audit. - [Check a supplier](https://mydomainrisk.com/check-a-supplier) - Due diligence before signing. - [MSP monthly report](https://mydomainrisk.com/msp-monthly-report) - Client bundles and evidence packs. ## Use cases - UK SMEs preparing for Cyber Essentials or supplier security questions. - Consultants and MSPs monitoring client domains and producing client-ready evidence. - Teams checking public domain posture, email-authentication readiness, suspicious links, and lookalike-domain risk. - Buyers reviewing a supplier's externally visible security posture before or during procurement. - Organisations running a live data-breach incident, their own or a supplier's, who need a defensible record of what was known and when. ## Product boundaries - Default checks are external and non-intrusive. - MyDomainRisk does not exploit systems, attempt credential access, brute force, fuzz, or run authenticated probing in the default product. - Public pages describe findings and practical remediation, not scoring weights, verdict thresholds, source-combination logic, model prompts, provider lists, or internal operating procedures. - Authenticated pages, admin pages, user dashboards, scan histories, API surfaces, and tokenised shared reports are not intended for crawler access. - Guidance pages describe general operational practice. They are not legal, regulatory, insurance or forensic advice, and duties depend on an organisation's role, sector, contracts and the people affected. ## Other - [News and product updates](https://mydomainrisk.com/news) - Monthly newsletters and product announcements. - [Developers](https://mydomainrisk.com/developers) - API access for Pro and MSP plans. - [Privacy](https://mydomainrisk.com/privacy) · [Security policy](https://mydomainrisk.com/security-policy) · [GDPR](https://mydomainrisk.com/gdpr) ## Company - Product: MyDomainRisk - Publisher: Huro Data Technologies Ltd, United Kingdom - Contact: support@mydomainrisk.com