phantomstrike.io

External attack surface monitoring

See what attackers already know about you.

Your DNS, email policies, and certificate history are public. PhantomStrike reads them the way an attacker would, scores your exposure, and watches for changes. No agents, no credentials, no access required.

Passive checks only. We read public DNS, certificate logs, and third-party data. We never touch your systems.

Results in secondsNo signup for the first scan
Sample reportfictional-company.com
Exposure report
1 critical, 2 warnings, 4 secure. Fix the red item first.
Email authentication (DMARC)
p=none, spoofable
Fix:Raise the policy from p=none to p=quarantine, then p=reject once the reports show every legitimate sender passing.
Sender policy (SPF)
Soft fail (~all) only, forged mail is accepted and flagged
Fix:Change the final mechanism to -all once every sender is listed, so forged mail is rejected rather than flagged.
Certificate authority control (CAA)
No CAA record, any authority can issue certificates
Fix:Add a CAA record naming only the certificate authorities you use, for example 0 issue "letsencrypt.org". Check every host that issues certificates for you first.
Mail signing (DKIM)
Signing key published (selector: google)
+ 3 checks passed: DNSSEC, MX, certificate logs
Get alerted when any of this changes.
Monitor a domain
01

Enter your domain

No signup for the first scan. Type the domain and go.

02

We read the public record

Public DNS, certificate transparency logs, third-party data. Nothing touches your infrastructure.

03

You get a scored report

Every finding rated, explained, and paired with the fix. A 0 to 100 score you can track.

What we check

Every scan reads the record an attacker reads

CheckWhat we readFreePro and up
Email spoofabilityDMARC policy and quality, the full SPF lookup chain against the 10-lookup limit, DKIM keys per sending provider
Mail transportMTA-STS and TLS-RPT records, so mail to you cannot be downgraded to plaintext
DNS integrityDNSSEC validation, CAA issuance limits, nameserver redundancy
Domain registrationExpiry date and registrar transfer lock from the public registry
CertificatesExpiry of your newest certificate, read from public logs rather than your server
Exposed subdomainsEvery hostname in certificate transparency logs, with sensitive-looking names (vpn, staging, admin) checked for whether they still answer
Mail routingPublished MX hosts and the providers behind them
Exposed servicesInternet-wide scan data for your hosts: risky open ports, no packets sent by us·
Leaked credentialsAccounts on your domain in known breach data·
Subdomain takeoverDangling records pointing at unclaimed cloud resources, confirmed with the provider, never with your hosts·
Lookalike domainsHundreds of typosquats of your brand (acme-login.com, acrne.com, acme.co) checked for registration and mail records, so you hear about a phishing domain before your customers do·

No access required

We never connect to your systems

Everything we report comes from public and third-party data: public DNS resolvers, certificate transparency logs, and licensed breach and scan datasets. We send no traffic to your servers, attempt no logins, and run no exploits. Human-led penetration testing is a separate, contract-signed engagement.

Reads public DNS through a public resolver
Reads certificate transparency logs
Reads third-party scan and breach datasets
Never port-scans, probes, or sends packets to your hosts
Never attempts logins or sends test mail
Never shares or sells your findings

Pricing

Scan free. Subscribe to stay watched.

FreeStarterProBusiness
Monthly price$0at checkoutat checkoutat checkout
Domains1310Unlimited
Scheduled re-scansOn demandWeeklyDailyDaily
Change alerts by email, Slack, Teams, or webhook·
Weekly digest email·
Client grouping for agencies and MSPs···
Score history and branded PDF reports
Exposed services, leaked credentials, takeover checks, lookalike domain monitoring··
Start freeChoose StarterChoose ProChoose Business

Current pricing is shown at checkout. Upgrade, downgrade, or cancel any time from your account.

Questions

Things people ask before they scan

Is scanning a domain legal?

Yes. Every check reads records the domain owner publishes to the world, or data from providers licensed to share it. Nothing here needs permission because nothing here touches the target.

Will it set off my alarms?

No. We never send a packet to your servers, so there is nothing for an IDS, WAF, or firewall to see. Your authoritative nameservers may see ordinary recursive queries from a public resolver, indistinguishable from any other lookup on the internet. If a data source is unreachable during a scan, the check is marked not measured rather than guessed, and it never raises an alert.

What do you store?

The scan results for your domains, so we can show history and detect changes. Findings are never shared, sold, or exposed through any public endpoint.

Can I scan a domain I do not own?

The free scan reads public records, the same as any DNS lookup. Continuous monitoring is for domains you are responsible for, and it is how most people check a vendor or an acquisition before signing.

How is the score calculated?

Start at 100. Each critical finding costs 22, each warning 9. 80 and up is solid, 50 to 79 is at risk, below 50 is exposed. Every point is explained by a finding you can fix.

Is this a penetration test?

No. This is passive, continuous monitoring. If you want humans actively testing your systems with your written authorization, that is a separate engagement we offer on request.

Seconds from now you will know your score.

Free, no signup, nothing installed.
Run free scan