External attack surface monitoring and protection
See what attackers already know about you.
Your DNS, email policies, and certificate history are public. PhantomStrike reads them the way an attacker would, scores your exposure, hands you the exact records that fix it, and tells you the moment anything drifts. No agents, no credentials, no access required.
Passive checks only. We read public DNS, certificate logs, and third-party data. We never touch your systems.
Scan
No signup for the first scan. We read public DNS, certificate logs, the registry, and third-party data. Nothing touches your infrastructure.
Fix
Every finding comes with the exact records for your DNS provider, a copy button, and a verify button that re-checks the moment you paste them.
Stay watched
We re-scan on a schedule and alert you when nameservers, mail routing, hostnames, or lookalike domains change. The score is a snapshot; the alerts are the product.
What we check
Every scan reads the record an attacker reads
| Check | What we read | Free | Pro and up |
|---|---|---|---|
| Email spoofability | DMARC policy and quality, the full SPF lookup chain against the 10-lookup limit, DKIM keys per sending provider | ||
| Mail transport | MTA-STS and TLS-RPT records, so mail to you cannot be downgraded to plaintext | ||
| DNS integrity | DNSSEC validation, CAA issuance limits, nameserver redundancy | ||
| Domain registration | Expiry date and registrar transfer lock from the public registry | ||
| Certificates | Expiry of your newest certificate, read from public logs rather than your server | ||
| Exposed subdomains | Every hostname in certificate transparency logs, with sensitive-looking names (vpn, staging, admin) checked for whether they still answer | ||
| Mail routing | Published MX hosts and the providers behind them | ||
| DNS inventory | Every record on your apex, every hostname that resolves and what it points at, dangling records, wildcard DNS, and the third-party services your records reveal | ||
| Exposed services | Internet-wide scan data for your hosts: risky open ports, no packets sent by us | · | |
| Leaked credentials | Accounts on your domain in known breach data | · | |
| Subdomain takeover | Dangling records pointing at unclaimed cloud resources, confirmed with the provider, never with your hosts | · | |
| Lookalike domains | Hundreds of typosquats of your brand (acme-login.com, acrne.com, acme.co) checked for registration and mail records, so you hear about a phishing domain before your customers do | · |
Protection
Detection tells you. Protection keeps you safe.
Fix packs
Every planThe exact records for your DNS provider under every finding, with the provider's entry quirks, a copy button, and a link to its console. A split DMARC record becomes one line; SPF gets the includes for your mail provider; CAA names the authorities your hosting actually uses.
Drift alerts
Paid plansNameserver or mail-routing changes are how domains get hijacked, so they page you as critical. New hostnames, new lookalikes with mail records, new verification tokens, and any finding that moves arrive by email, Slack, Teams, or webhook.
Hosted MTA-STS
Paid plansStops mail to you being downgraded to plaintext. It needs a policy file on an HTTPS host, so we serve it: add one CNAME and two TXT records, start in testing, switch to enforce when the reports are clean.
Lookalike blocklist feed
Pro and upEvery typosquat registered by someone else, across all your domains, as a URL your DNS filter, mail gateway, or firewall pulls on a schedule. Employees cannot reach or receive from them, and the list grows as new ones appear.
Takedown drafts
Pro and upOne click looks up the registrar and abuse mailbox for a lookalike and opens a ready-to-send report, with the Google Safe Browsing report link beside it.
Evidence on demand
Every planA dated, branded PDF of the latest scan with the fix records included, a score history, a per-scan diff, and a CSV of every DNS record. What an insurer, auditor, or client asks for, already written.
No access required
We never connect to your systems
Everything we report comes from public and third-party data: public DNS resolvers, certificate transparency logs, and licensed breach and scan datasets. We send no traffic to your servers, attempt no logins, and run no exploits. Human-led penetration testing is a separate, contract-signed engagement.
Pricing
Scan free. Subscribe to stay watched and protected.
| Free | Starter | Pro | Business | |
|---|---|---|---|---|
| Monthly price | $0 | at checkout | at checkout | at checkout |
| Domains | 1 | 3 | 10 | Unlimited |
| Scheduled re-scans | On demand | Weekly | Daily | Daily |
| Change alerts by email, Slack, Teams, or webhook | · | |||
| Fix packs: exact records for your DNS provider | ||||
| Hosted MTA-STS policy | · | |||
| Lookalike blocklist feed and takedown drafts | · | · | ||
| Weekly digest email | · | |||
| Client grouping for agencies and MSPs | · | · | · | |
| Score history and branded PDF reports | ||||
| Exposed services, leaked credentials, takeover checks, lookalike domain monitoring | · | · | ||
| Start free | Choose Starter | Choose Pro | Choose Business |
Current pricing is shown at checkout. Upgrade, downgrade, or cancel any time from your account.
Questions
Things people ask before they scan
Is scanning a domain legal?
Yes. Every check reads records the domain owner publishes to the world, or data from providers licensed to share it. Nothing here needs permission because nothing here touches the target.
Will it set off my alarms?
No. We never send a packet to your servers, so there is nothing for an IDS, WAF, or firewall to see. Your authoritative nameservers may see ordinary recursive queries from a public resolver, indistinguishable from any other lookup on the internet. If a data source is unreachable during a scan, the check is marked not measured rather than guessed, and it never raises an alert.
What do you store?
The scan results for your domains, so we can show history and detect changes. Findings are never shared, sold, or exposed through any public endpoint.
Can I scan a domain I do not own?
The free scan reads public records, the same as any DNS lookup. Continuous monitoring is for domains you are responsible for, and it is how most people check a vendor or an acquisition before signing.
How is the score calculated?
Start at 100. Each critical finding costs 22, each warning 9. 80 and up is solid, 50 to 79 is at risk, below 50 is exposed. Every point is explained by a finding you can fix.
Do you fix things for me?
Every open finding carries a fix pack: the exact records for your DNS provider, a link to its console, and a verify button. You paste, we confirm. We never write to your DNS. The one thing we run for you is the MTA-STS policy file, because it needs a web server and most companies do not want to stand one up for a text file.
What happens after the first scan?
On a paid plan we re-scan daily or weekly and alert you the moment something drifts: a nameserver or MX change that looks like a hijack, a new hostname in the certificate logs, a new lookalike domain that can send mail, a new SaaS verification token in your TXT records. A Monday digest sums up the week and a dated PDF is there whenever an insurer or auditor asks for evidence.
What is a lookalike domain and what can I do about it?
A registered name one character away from yours, like acrne.com or acme-login.com. We check a few hundred variants on every Pro scan and flag the ones registered by someone else, especially those with mail records. From there you get a blocklist feed your DNS filter or mail gateway pulls automatically, and a one-click takedown report addressed to the registrar's abuse desk.
Is this a penetration test?
No. This is passive, continuous monitoring. If you want humans actively testing your systems with your written authorization, that is a separate engagement we offer on request.