Non-intrusive external scanning

Tracking 50 client domains by hand?

MyDomainRisk MSP is the multi-customer tier for service providers. Group domains by client, run daily scheduled scans, track owner/status/due dates in per-client Priorities, generate branded client-ready report bundles with a pre-download report check, invite read-only client contacts, and scope Alerts per client. MSP is £99/month and includes 250 security domains plus 150 authenticity domains.

No password. No credit card. Just your email to receive results.

One sign-in, both apps — Free, Pro or MSP covers security and authenticity. No second subscription.

Hosted on security-certified infrastructure providers.

acmecorp.com

Security posture: critical

34

/ 100

TLS / Certificate
18/30
Security headers
9/30
DNS / Email
7/20
Internet exposure
10/20

CRITICAL FINDINGS

!

Domain can be impersonated to send phishing email — no DMARC enforcement

Critical
!

3 employee credentials found in stealer logs — active breach risk

Critical
!

Subdomain hijacking vulnerability — attacker can host content on affected domain

High
!

TLS certificate expires in 6 days — site will show browser security warnings

High
!

2 lookalike domains actively resolving — phishing infrastructure detected

High
Scan a domain free — 60 seconds →

No password · No credit card · Just your email

50+

Security checks

< 60s

Scan time

Clear

Risk rating

40+

Intel sources

Surface Compliance

Every scan includes advisory compliance cards alongside the main risk rating — externally visible evidence only, not a certification audit.

GDPR Technical BaselineFree + Pro

UK & EU — Article 32 technical advisory. ⓘ What's checked?

  • HTTPS redirect enforcedArt. 32(1)(a)Free
  • Privacy policy accessibleArt. 13 / 14Free
  • Cookie consent mechanismePrivacy / Art. 7Free
  • No mixed contentArt. 32(1)(a)Pro
  • Vulnerability disclosure policyArt. 32(1)(d)Pro
  • Third-party tracker enumerationArt. 28 / Art. 13Pro

Advisory only. A passing score does not constitute GDPR compliance — organisational measures, DPAs, and data retention policies are out of scope.

US ComplianceFree + Pro

PCI DSS 4.0 Surface + CCPA/CPRA advisory review. ⓘ What's checked?

PCI DSS 4.0 Surface

  • HTTPS enforcement
  • TLS protocol health
  • Certificate validity
  • HSTS presence
  • Known vulnerability exposure
  • Heartbleed exposure
  • Exposed database services
  • Public cloud bucket exposure
  • Mail transport security
  • Open relay risk
  • security.txt disclosure policy

US Privacy — CCPA / CPRA

  • HTTPS enforcement
  • Privacy policy presence
  • 'Do Not Sell or Share' opt-out mechanism
  • Cookie consent / CMP
  • Global Privacy Control support

Advisory only. Not a PCI DSS certification or a legal CCPA compliance assessment — formal audits, cardholder-data-environment scoping, and organisational controls remain out of scope.

Sample Open Source Intel Providers

Google Safe BrowsingHave I Been PwnedHudsonRockShodanOpenPhish

One subscription, every lens. Cyber Essentials · GDPR · PCI · CCPA · DMARC · Suppliers · Invoice · Crypto · MSP. See them all ↓

MSP tier · £99/month · One subscription, both apps

What the MSP plan adds to Pro

MSP extends Pro with client grouping, client-ready report bundles, delegated read-only portal access, an audit trail, per-client Priorities work queues and Alerts, and a 5× capacity step-up on the security side.

Portfolio clients

Group tracked domains under named customer estates. Each client can have its own domains, schedules, branding, report bundle, delegated contacts, Priorities work queue, and Alert scope.

Client-ready report bundles

Export a branded PDF bundle for each client, ordered by lowest-scored domains first. Save logo URL/upload, colour, optional footer note, and Prepared by / Prepared for fields per customer.

Report check before download

Before exporting, review scan coverage, at-risk count, branding status, lowest-scored domains, unscanned warnings, and the non-intrusive scope note so the bundle is safe to send.

Read-only client portal

Invite client contacts to see only their own dashboard and report bundle in /client-portal. They cannot edit domains, schedules, branding, contacts, alerts, or other clients.

Per-client Priorities and Alerts

Filter the risk-ranked Priorities work queue to one customer, track owner, status, due dates and overdue work, export per-client CSVs, suppress accepted risks by client, and scope alert rules so each customer's changes route separately.

£99/month with higher caps

Track 250 security domains and 150 authenticity domains. Client audit records branding edits, logo uploads, invites, revokes, accepts, and portal views without storing old/new branding values.

Everything domain security needs

A comprehensive scan covering all the externally observable security signals that matter — with no special access or agent required.

Included free

Free

Infostealer Exposure

Detects employee credentials harvested by malware.

Free

Attack Scenarios

Plain-English narratives of how detected weaknesses could be exploited.

Free

DNS Security

Verifies email authentication records to prevent spoofing.

Free

Fix It with Claude

One-click remediation guidance for every finding.

Free

Subdomain Takeover Detection

Finds dangling DNS records attackers could claim.

Free

Domain Exposure

Spots lookalike domains used for brand phishing.

Free

Cloud Storage Exposure

Detects publicly accessible cloud storage buckets.

Free

TLS & SSL Analysis

Validates certificates, ciphers, and encryption strength.

Free

Security Headers

Checks that your web server sends all major browser security headers.

Free

GDPR Technical Baseline

Checks the externally verifiable technical measures required under GDPR Article 32.

Free

US Compliance — PCI DSS + CCPA

Advisory technical checks for the US market.

Free

TLS-inspection transparency

We name the corporate appliance instead of saying 'TLS error'.

Pro features
Pro

Data Breach Detection

Flags compromised credentials from known breach databases.

Pro

PDF Security Reports

Export a shareable report for leadership or auditors.

Pro

Scheduled Monitoring

Automated weekly or monthly scans on Pro; daily schedules on MSP.

Up and running in three steps

No installation. No agents. No access keys.

1

Enter your email

No password, no credit card. We send you a secure sign-in link — click it and you're in.

2

We run the checks

MyDomainRisk performs 50+ non-intrusive security checks — TLS, headers, DNS, network infrastructure, threat intelligence, breaches, exposure — in under a minute.

3

Get your risk report

Review the risk rating, prioritised findings and supporting evidence in the dashboard. Pro users can download a PDF report to share with leadership or auditors.

Example findings

Remediation actions for acmecorp.com

Every finding comes with a plain-English explanation of the risk and a specific action to fix it.

No DMARC enforcement — domain can be spoofed
Critical

What this means

There is no DMARC record published for this domain. This means any attacker can send email that appears to come from the domain — staff, customers, and partners will see the brand in the From address with no way to distinguish it from a genuine message.

How to fix it

Publish a DMARC TXT record at _dmarc.yourdomain.com starting with p=quarantine to begin collecting reports. Once all legitimate senders are confirmed in SPF and DKIM, upgrade to p=reject to block spoofed email entirely.

Employee credentials found in stealer logs
Critical

What this means

Three sets of employee credentials associated with this domain have been identified in infostealer malware logs. These are active, real-world exposures — the affected accounts may already be accessible to threat actors.

How to fix it

Immediately reset passwords for affected accounts and revoke any active sessions. Enable MFA on all accounts if not already enforced. Notify affected employees and review access logs for signs of unauthorised access in the preceding 90 days.

Subdomain hijacking vulnerability detected
High

What this means

A subdomain has a dangling CNAME record pointing to a cloud service (e.g. GitHub Pages, Heroku, Netlify) where the target resource no longer exists. An attacker can claim that resource and host arbitrary content — phishing pages, malware, or credential-harvesting forms — under the affected domain.

How to fix it

Remove the dangling CNAME record from your DNS immediately. If the subdomain is still needed, reclaim the corresponding resource in the cloud platform before re-publishing. Audit all subdomains regularly for stale records.

TLS certificate expires in 6 days
High

What this means

The TLS certificate for this domain expires in under a week. When it expires, all major browsers will display a full-page security warning to visitors, blocking access until the certificate is renewed. This affects both customer trust and any automated systems that validate certificates.

How to fix it

Renew the certificate immediately through your certificate authority or hosting provider. If using Let's Encrypt, check that the auto-renewal cron job or ACME client is running correctly — it should renew automatically at 30 days remaining.

Lookalike domains actively resolving
High

What this means

Two typosquatted domains closely resembling this domain are registered and actively resolving — meaning they are live and potentially serving content. These are commonly used to conduct phishing campaigns against your customers and employees.

How to fix it

Monitor the identified lookalike domains via threat intelligence feeds. Where feasible, register the most likely typosquat variants defensively. If a lookalike is hosting phishing content, report it to the registrar and relevant abuse contacts for takedown.

Every scan generates a full remediation plan like this — specific to the domain under review, ready to share with your team or auditors.

Not sure where to start?

Fix It with Claude

Every finding in your report has a Fix with Claude button. One click opens Claude.ai with the relevant domain details already filled in. Just hit send — Claude will tell you exactly what to change, in plain English, written for the detected setup.

Step-by-step guides

Every finding also links to a written guide with the exact DNS record or config value to add, instructions for the most common platforms, and how to verify the fix worked. No jargon.

Pricing

Simple, transparent pricing

Start free. Upgrade when you need scheduled monitoring, more domains, or deeper analysis.

One account, both apps — one subscription. Free, Pro or MSP, a single MyDomainRisk sign-in unlocks both apps — the security app (harden the external configuration of any domain you want to assess) and the authenticity app (check whether a suspicious link or supplier domain is genuine). Same non-intrusive checks underneath, different lens depending on the question you're asking. One tier, one subscription, both tools.

For checking any domain

Free

£0/month

No credit card required. Start scanning immediately.

Full domain scan — free, 60 seconds
  • 5 domains · 5 scans per day · last 5 scans per domain
  • Risk rating with prioritised findings — TLS, headers, DNS, exposure and more
  • DNS & email security — detect spoofing risk from SPF, DMARC and DKIM gaps
  • Subdomain takeover detection
  • Lookalike domain detection — spot phishing infrastructure targeting your brand
  • Attack Scenarios — plain-English risk narratives from your scan findings
  • Cloud storage exposure — public S3, GCS, and Azure Blob buckets
  • Infostealer exposure — employee and user credential counts from malware logs
  • Modern Internet Standards report — HSTS preload, OCSP stapling, HTTP/3, IPv6, DANE, RPKI and more
  • GDPR Technical Baseline — UK + EU advisory review on every scan
  • US Compliance advisory — PCI DSS Surface + CCPA/CPRA review on every scan
  • Fix with Claude — one-click remediation guidance for every finding

For IT teams and consultants monitoring multiple domains

Pro

£19/month

Everything you need to monitor a full domain portfolio.

Upgrade to Pro
  • Everything in Free
  • 50 security domains · 50 scans per day · 50 history per domain
  • Portfolio cockpit + EPSS-ranked Priorities workflow across every domain you track
  • Alerts to Slack, Microsoft Teams or any HTTPS webhook (HMAC-signed) — on new criticals, risk-rating changes, verdict changes, cert expiry, repeated failures
  • Scheduled scans — weekly or monthly
  • Data breach detection on every scan
  • Infostealer full detail — infection records and credential exposure
  • Track your security posture over time with scan-to-scan comparison
  • Bulk scan up to 50 domains in one run — ideal for one-off audits
  • PDF security report ready to share with leadership or auditors
  • IP reputation and page threat analysis
  • US Compliance — supporting evidence and remediation guidance
  • GDPR Technical Baseline — full Pro analysis

50 security domains · 50 scans per day · 50 history per domain

Managing multiple separate customer estates?See MSP →

No lock-in. Cancel any time, or downgrade at the end of the period and keep Pro until the billing date.

For service providers

For consultancies, MSPs and agencies managing many client estates

MSP

£99/month

Everything in Pro, plus Portfolio clients, branded report bundles with report checks, delegated read-only portal access, a client audit trail, and per-client Priorities work queues and Alerts.

Upgrade to MSP
  • Everything in Pro
  • Bulk scan and investigate up to 250 domains per list
  • Daily scheduled scans for client portfolios
  • Portfolio clients — group tracked domains under named customer estates
  • Client report bundles — branded PDF summaries ordered by lowest-scored domains first
  • Report check before download — coverage, at-risk count, branding status and unscanned warnings
  • Prepared by / Prepared for fields, logo URL/upload, colour and optional footer note per client
  • Delegated read-only client portal access for customer contacts
  • Client audit trail for branding, logo and portal actions
  • Per-client Priorities and Alerts — track owner/status/due dates, filter, export, suppress and route by customer
  • 250 security domains (5× Pro) · 250 scans per day (5× Pro) · 50 history per domain
  • 150 authenticity domains (3× Pro) · 150 investigations per day (3× Pro) · 10 history per domain
  • One subscription covers both apps — security AND authenticity
  • Switch between Pro and MSP any time via Stripe customer portal (with proration)

Need more than 250 security or 150 authenticity domains? support@mydomainrisk.com

No lock-in. Cancel any time, or downgrade to Pro / Free at period end.

Frequently asked questions

Do I need a credit card to try it?

No. The Free plan requires only your email address — no payment details at any point.

Will this affect my website or cause any disruption?

No. Every check is a passive, external observation — we query publicly available data and DNS records only. Nothing is sent to your server and nothing is changed.

Can I cancel my Pro subscription at any time?

Yes. You can downgrade to Free or cancel immediately from your account page. No contracts, no minimum term.

What happens to my data after a scan?

Scan results are stored against your account in line with your plan limits. You can export or delete your data at any time. See our Privacy Policy for full details.

Ready to check a domain?

Free for up to 5 domains. No card required. Pro plans unlock bulk scanning, scheduled monitoring, and full breach reports.

Full domain scan — free, 60 seconds