External security assessment
See what your domain exposes
Verify ownership, run a controlled security assessment, and receive a clear report with practical fixes.
$9.00 one-time · no subscription · ownership verified before anything runs
Ownership verified first
Nothing is assessed until you prove control of the domain.
Controlled, non-destructive
No exploitation, no brute force, nothing installed.
Private report delivery
Sent only to the email address you provide — never posted publicly.
One-time payment
A single price per assessment. No subscription, nothing recurring.
How it works
- 01
Enter your domain
Tell us the domain you own. Nothing is assessed yet.
- 02
Verify ownership
Add one DNS TXT record. We confirm it automatically.
- 03
Pay once
One assessment, one price, confirmed before anything runs.
- 04
Receive your report
A branded PDF, emailed when the assessment finishes.
What the scan checks
Five categories, assessed non-destructively from the public internet — the same way any visitor or mail server sees your domain.
DNS configuration
Apex resolution and mail-exchanger records — the foundation everything else depends on.
Email authentication
SPF, DKIM and DMARC — the records that decide whether mail claiming your domain can be verified.
TLS and certificates
Whether HTTPS is served, the certificate’s validity and expiry, and which TLS versions are negotiated.
HTTP security headers
HSTS, Content-Security-Policy, framing controls, content-type sniffing, and the HTTPS redirect.
Public exposure signals
Hostnames published for your domain in certificate-transparency logs, recorded as inventory.
A report you can act on
Every finding is ranked by severity and explained in plain language, with a recommended fix — not a raw scanner log.
Example report
example-company.com
62
Security score
out of 100
Findings are ranked by severity, each with the affected area, a plain-language explanation, and a recommended fix — nothing left as a code or a checklist item to decode.
No DMARC record was published, so mail claiming to be from this domain cannot be authenticated.
Recommended fix — Publish a DMARC record starting at p=none to gather reports before enforcing rejection.
The site does not send a Strict-Transport-Security header, so browsers can be downgraded to plain HTTP.
Recommended fix — Add Strict-Transport-Security with a long max-age once every subdomain serves HTTPS correctly.
The certificate is valid but expires in 11 days, with no indication of an automated renewal in place.
Recommended fix — Confirm renewal is automated, or renew manually well before the expiry date.
Frequently asked questions
What does Wraith scan?
DNS configuration, email authentication (SPF, DKIM, DMARC), TLS and certificates, HTTP security headers, and hostnames publicly recorded for your domain. See "What we check" above.
How do I verify my domain?
You add one DNS TXT record we generate for you. Once it publishes, we confirm it automatically — that proves you control the domain before anything is assessed.
Is the assessment safe?
Yes. It only reads DNS records, completes a TLS handshake, and requests one page over HTTP and HTTPS per authorized hostname — the same requests any visitor’s browser makes.
Does Wraith exploit vulnerabilities?
No. Wraith does not attempt exploitation, port scanning, password guessing, or authenticated access. It observes published configuration; it never tries to use a weakness it finds.
How long does a scan take?
Most assessments finish within a few minutes of payment. You can close the page — we email the report when it’s ready.
How will I receive the report?
By email, as a branded PDF, sent to the address you provide at checkout. Nothing is posted publicly.
Can I scan a domain I do not own?
No. Verification and an explicit authorization confirmation are required before any assessment runs, for every domain, every time.
Is this a subscription?
No. Each assessment is a single one-time payment. Nothing renews automatically.
