phantomstrike.io

External attack surface monitoring and protection

See what attackers already know about you.

Your DNS, email policies, and certificate history are public. PhantomStrike reads them the way an attacker would, scores your exposure, hands you the exact records that fix it, and tells you the moment anything drifts. No agents, no credentials, no access required.

Passive checks only. We read public DNS, certificate logs, and third-party data. We never touch your systems.

Results in secondsNo signup for the first scan
Sample reportfictional-company.com
Exposure report
1 critical, 2 warnings, 4 secure. Fix the red item first.
Email authentication (DMARC)
p=none, spoofable
Fix:Raise the policy from p=none to p=quarantine, then p=reject once the reports show every legitimate sender passing.
Sender policy (SPF)
Soft fail (~all) only, forged mail is accepted and flagged
Fix:Change the final mechanism to -all once every sender is listed, so forged mail is rejected rather than flagged.
Certificate authority control (CAA)
No CAA record, any authority can issue certificates
Fix:Add a CAA record naming only the certificate authorities you use, for example 0 issue "letsencrypt.org". Check every host that issues certificates for you first.
Mail signing (DKIM)
Signing key published (selector: google)
+ 3 checks passed: DNSSEC, MX, certificate logs
Get alerted when any of this changes.
Monitor a domain
01

Scan

No signup for the first scan. We read public DNS, certificate logs, the registry, and third-party data. Nothing touches your infrastructure.

02

Fix

Every finding comes with the exact records for your DNS provider, a copy button, and a verify button that re-checks the moment you paste them.

03

Stay watched

We re-scan on a schedule and alert you when nameservers, mail routing, hostnames, or lookalike domains change. The score is a snapshot; the alerts are the product.

What we check

Every scan reads the record an attacker reads

CheckWhat we readFreePro and up
Email spoofabilityDMARC policy and quality, the full SPF lookup chain against the 10-lookup limit, DKIM keys per sending provider
Mail transportMTA-STS and TLS-RPT records, so mail to you cannot be downgraded to plaintext
DNS integrityDNSSEC validation, CAA issuance limits, nameserver redundancy
Domain registrationExpiry date and registrar transfer lock from the public registry
CertificatesExpiry of your newest certificate, read from public logs rather than your server
Exposed subdomainsEvery hostname in certificate transparency logs, with sensitive-looking names (vpn, staging, admin) checked for whether they still answer
Mail routingPublished MX hosts and the providers behind them
DNS inventoryEvery record on your apex, every hostname that resolves and what it points at, dangling records, wildcard DNS, and the third-party services your records reveal
Exposed servicesInternet-wide scan data for your hosts: risky open ports, no packets sent by us·
Leaked credentialsAccounts on your domain in known breach data·
Subdomain takeoverDangling records pointing at unclaimed cloud resources, confirmed with the provider, never with your hosts·
Lookalike domainsHundreds of typosquats of your brand (acme-login.com, acrne.com, acme.co) checked for registration and mail records, so you hear about a phishing domain before your customers do·

Protection

Detection tells you. Protection keeps you safe.

Fix packs

Every plan

The exact records for your DNS provider under every finding, with the provider's entry quirks, a copy button, and a link to its console. A split DMARC record becomes one line; SPF gets the includes for your mail provider; CAA names the authorities your hosting actually uses.

Drift alerts

Paid plans

Nameserver or mail-routing changes are how domains get hijacked, so they page you as critical. New hostnames, new lookalikes with mail records, new verification tokens, and any finding that moves arrive by email, Slack, Teams, or webhook.

Hosted MTA-STS

Paid plans

Stops mail to you being downgraded to plaintext. It needs a policy file on an HTTPS host, so we serve it: add one CNAME and two TXT records, start in testing, switch to enforce when the reports are clean.

Lookalike blocklist feed

Pro and up

Every typosquat registered by someone else, across all your domains, as a URL your DNS filter, mail gateway, or firewall pulls on a schedule. Employees cannot reach or receive from them, and the list grows as new ones appear.

Takedown drafts

Pro and up

One click looks up the registrar and abuse mailbox for a lookalike and opens a ready-to-send report, with the Google Safe Browsing report link beside it.

Evidence on demand

Every plan

A dated, branded PDF of the latest scan with the fix records included, a score history, a per-scan diff, and a CSV of every DNS record. What an insurer, auditor, or client asks for, already written.

No access required

We never connect to your systems

Everything we report comes from public and third-party data: public DNS resolvers, certificate transparency logs, and licensed breach and scan datasets. We send no traffic to your servers, attempt no logins, and run no exploits. Human-led penetration testing is a separate, contract-signed engagement.

Reads public DNS through a public resolver
Reads certificate transparency logs
Reads third-party scan and breach datasets
Never port-scans, probes, or sends packets to your hosts
Never attempts logins or sends test mail
Never writes to your DNS or your systems; fixes are records you paste yourself
Never shares or sells your findings

Pricing

Scan free. Subscribe to stay watched and protected.

FreeStarterProBusiness
Monthly price$0at checkoutat checkoutat checkout
Domains1310Unlimited
Scheduled re-scansOn demandWeeklyDailyDaily
Change alerts by email, Slack, Teams, or webhook·
Fix packs: exact records for your DNS provider
Hosted MTA-STS policy·
Lookalike blocklist feed and takedown drafts··
Weekly digest email·
Client grouping for agencies and MSPs···
Score history and branded PDF reports
Exposed services, leaked credentials, takeover checks, lookalike domain monitoring··
Start freeChoose StarterChoose ProChoose Business

Current pricing is shown at checkout. Upgrade, downgrade, or cancel any time from your account.

Questions

Things people ask before they scan

Is scanning a domain legal?

Yes. Every check reads records the domain owner publishes to the world, or data from providers licensed to share it. Nothing here needs permission because nothing here touches the target.

Will it set off my alarms?

No. We never send a packet to your servers, so there is nothing for an IDS, WAF, or firewall to see. Your authoritative nameservers may see ordinary recursive queries from a public resolver, indistinguishable from any other lookup on the internet. If a data source is unreachable during a scan, the check is marked not measured rather than guessed, and it never raises an alert.

What do you store?

The scan results for your domains, so we can show history and detect changes. Findings are never shared, sold, or exposed through any public endpoint.

Can I scan a domain I do not own?

The free scan reads public records, the same as any DNS lookup. Continuous monitoring is for domains you are responsible for, and it is how most people check a vendor or an acquisition before signing.

How is the score calculated?

Start at 100. Each critical finding costs 22, each warning 9. 80 and up is solid, 50 to 79 is at risk, below 50 is exposed. Every point is explained by a finding you can fix.

Do you fix things for me?

Every open finding carries a fix pack: the exact records for your DNS provider, a link to its console, and a verify button. You paste, we confirm. We never write to your DNS. The one thing we run for you is the MTA-STS policy file, because it needs a web server and most companies do not want to stand one up for a text file.

What happens after the first scan?

On a paid plan we re-scan daily or weekly and alert you the moment something drifts: a nameserver or MX change that looks like a hijack, a new hostname in the certificate logs, a new lookalike domain that can send mail, a new SaaS verification token in your TXT records. A Monday digest sums up the week and a dated PDF is there whenever an insurer or auditor asks for evidence.

What is a lookalike domain and what can I do about it?

A registered name one character away from yours, like acrne.com or acme-login.com. We check a few hundred variants on every Pro scan and flag the ones registered by someone else, especially those with mail records. From there you get a blocklist feed your DNS filter or mail gateway pulls automatically, and a one-click takedown report addressed to the registrar's abuse desk.

Is this a penetration test?

No. This is passive, continuous monitoring. If you want humans actively testing your systems with your written authorization, that is a separate engagement we offer on request.

Seconds from now you will know your score. Minutes from now you can fix it.

Free, no signup, nothing installed. Every finding comes with the records that fix it.
Run free scan