External attack surface monitoring
See what attackers already know about you.
Your DNS, email policies, and certificate history are public. PhantomStrike reads them the way an attacker would, scores your exposure, and watches for changes. No agents, no credentials, no access required.
Passive checks only. We read public DNS, certificate logs, and third-party data. We never touch your systems.
Enter your domain
No signup for the first scan. Type the domain and go.
We read the public record
Public DNS, certificate transparency logs, third-party data. Nothing touches your infrastructure.
You get a scored report
Every finding rated, explained, and paired with the fix. A 0 to 100 score you can track.
What we check
Every scan reads the record an attacker reads
| Check | What we read | Free | Pro and up |
|---|---|---|---|
| Email spoofability | DMARC policy and quality, the full SPF lookup chain against the 10-lookup limit, DKIM keys per sending provider | ||
| Mail transport | MTA-STS and TLS-RPT records, so mail to you cannot be downgraded to plaintext | ||
| DNS integrity | DNSSEC validation, CAA issuance limits, nameserver redundancy | ||
| Domain registration | Expiry date and registrar transfer lock from the public registry | ||
| Certificates | Expiry of your newest certificate, read from public logs rather than your server | ||
| Exposed subdomains | Every hostname in certificate transparency logs, with sensitive-looking names (vpn, staging, admin) checked for whether they still answer | ||
| Mail routing | Published MX hosts and the providers behind them | ||
| Exposed services | Internet-wide scan data for your hosts: risky open ports, no packets sent by us | · | |
| Leaked credentials | Accounts on your domain in known breach data | · | |
| Subdomain takeover | Dangling records pointing at unclaimed cloud resources, confirmed with the provider, never with your hosts | · | |
| Lookalike domains | Hundreds of typosquats of your brand (acme-login.com, acrne.com, acme.co) checked for registration and mail records, so you hear about a phishing domain before your customers do | · |
No access required
We never connect to your systems
Everything we report comes from public and third-party data: public DNS resolvers, certificate transparency logs, and licensed breach and scan datasets. We send no traffic to your servers, attempt no logins, and run no exploits. Human-led penetration testing is a separate, contract-signed engagement.
Pricing
Scan free. Subscribe to stay watched.
| Free | Starter | Pro | Business | |
|---|---|---|---|---|
| Monthly price | $0 | at checkout | at checkout | at checkout |
| Domains | 1 | 3 | 10 | Unlimited |
| Scheduled re-scans | On demand | Weekly | Daily | Daily |
| Change alerts by email, Slack, Teams, or webhook | · | |||
| Weekly digest email | · | |||
| Client grouping for agencies and MSPs | · | · | · | |
| Score history and branded PDF reports | ||||
| Exposed services, leaked credentials, takeover checks, lookalike domain monitoring | · | · | ||
| Start free | Choose Starter | Choose Pro | Choose Business |
Current pricing is shown at checkout. Upgrade, downgrade, or cancel any time from your account.
Questions
Things people ask before they scan
Is scanning a domain legal?
Yes. Every check reads records the domain owner publishes to the world, or data from providers licensed to share it. Nothing here needs permission because nothing here touches the target.
Will it set off my alarms?
No. We never send a packet to your servers, so there is nothing for an IDS, WAF, or firewall to see. Your authoritative nameservers may see ordinary recursive queries from a public resolver, indistinguishable from any other lookup on the internet. If a data source is unreachable during a scan, the check is marked not measured rather than guessed, and it never raises an alert.
What do you store?
The scan results for your domains, so we can show history and detect changes. Findings are never shared, sold, or exposed through any public endpoint.
Can I scan a domain I do not own?
The free scan reads public records, the same as any DNS lookup. Continuous monitoring is for domains you are responsible for, and it is how most people check a vendor or an acquisition before signing.
How is the score calculated?
Start at 100. Each critical finding costs 22, each warning 9. 80 and up is solid, 50 to 79 is at risk, below 50 is exposed. Every point is explained by a finding you can fix.
Is this a penetration test?
No. This is passive, continuous monitoring. If you want humans actively testing your systems with your written authorization, that is a separate engagement we offer on request.