See what an attacker sees on your domain
Most breaches start on an internet-facing asset somebody forgot: a test subdomain, an exposed admin panel, a certificate nobody renews. The snapshot shows you yours on one page, before an attacker or an auditor finds them.
Free · passive checks only · verified domain owners · reviewed by a person
One page, three answers
A short, plain-English read of your internet-facing footprint, with the one thing we would fix first.
What is out there
The hosts and subdomains that resolve publicly under your domain, including the ones nobody listed.
What looks exposed
Admin panels, dashboards and services visible from the internet, plus expired certificates and deprecated protocols.
Who is using it
Where an exposure matches what attackers are exploiting right now, we say so and cite the source.
From request to inbox
We only read what is already public. Nothing is tested or attacked without a signed scope.
Tell us the domain
Use your work email at that domain.
We confirm it is yours
A snapshot only goes to someone who can receive email at the domain being checked.
Passive read, human review
DNS and certificate records and what internet scanners have already seen. A person reviews every finding.
Your snapshot
One page in your inbox within two business days, with the one thing we would fix first.
A snapshot is a first look, not a pentest
The snapshot reads what is public. It does not try anything, so it cannot prove what is exploitable. If an audit, a security questionnaire or an enterprise deal is waiting on an independent pentest report, skip the queue and book a 15-minute scoping call.
Book a scoping callFour details, then we get to work
Use your email at the domain you want checked. That is how we know the snapshot goes to the right people.
We use these details to prepare and send your snapshot and to follow up about it. Privacy policy.
Before you ask
Is it really free?
Yes. No card, no contract. If the snapshot shows something you want tested properly, we can talk about a scoped pentest. If not, the snapshot is yours to keep.
Do you scan or attack my systems?
No. The snapshot uses only information that is already public: DNS and certificate records and what internet scanners have already seen. Active testing only happens under a signed scope and rules of engagement.
Why do you need an email at my domain?
So a snapshot only goes to people inside the organization it describes. We won't send one to an address outside the domain being checked.
Who reads it before it reaches me?
A person at XEUS reviews every snapshot before it is sent, so you get findings worth your time rather than raw tool output.
Need a pentest report for a deadline? Book a 15-minute scoping call.