Nothing accumulates
Monitoring a whole portfolio is the same safe observation repeated. There is no cumulative load and nothing compounds across domains or across weeks.
Non-intrusive external scanning
We observe; we don't touch
Trusting a security tool means knowing exactly what it does — and what it will never do. This page is that contract, in plain English.
The short version.
Every check looks only at what a domain already shows the public internet. Nothing is installed, nothing is logged into, nothing is attacked. That is why a check needs no access, no agreement and no agent: it reads what is already published, causes no disruption, and changes nothing.
One rule decides what is in a scan and what is not.
Every MyDomainRisk check is a non-intrusive external observation. We look at what a domain already shows to the public internet — its DNS records, its certificates, the headers its website sends, what public threat-intelligence sources say about it. Website protocol checks complete a small, bounded set of TLS handshakes without sending application data. They do not enumerate ciphers or attempt exploitation. Collection records for DNSSEC, disclosure files and cloud storage distinguish completed, incomplete and unavailable checks; completed collection is not a security pass. Historical reports retain their original evidence. RPKI routing intelligence is currently unavailable. Published vulnerability intelligence adds context without sending additional probes to the target.
The question every MSP and multi-domain owner asks before turning on scheduled monitoring.
Monitoring a whole portfolio is the same safe observation repeated. There is no cumulative load and nothing compounds across domains or across weeks.
A scheduled scan across hundreds of domains needs no agreement and no coordination with whoever runs them.
You will not knock a client's site over, trip their firewall alerting, or have to explain yourself to their IT provider afterwards.
A weekly scan puts no more load on any one domain than a search engine visiting the homepage.
Eight categories of publicly visible signal. All of it is information the domain already publishes.
Certificate validity and expiry, plus bounded TLS 1.0–1.3 handshakes on website port 443 on every plan. Unavailable probes remain unverified; this does not enumerate ciphers or certify the configuration.
Published email records, observed DKIM key structure, and MTA-STS policy syntax and mail-server matching. DNSSEC validation is reported separately from signing-record presence. Unavailable evidence remains unverified; these checks do not test actual message authentication.
The protective HTTP headers your site sends with every page.
Published service and vulnerability observations, supplemented by bounded connection checks. Dated known-exploitation intelligence helps prioritise reported vulnerabilities without claiming compromise or changing the domain score.
Registration expiry, transfer locks and DNS configuration. Pro/MSP full scans automatically review up to 50 related hosts per scanned domain using public certificate records and bounded DNS/HTTPS checks. Daily monitoring skips that review. Discovery is incomplete and indicators need ownership review; they do not confirm takeover or change the main score.
Registered domains that imitate yours — the raw material of phishing against your customers and staff.
Whether your domain, infrastructure, or employee credentials appear in trusted public and commercial threat feeds.
The externally verifiable subset of GDPR Article 32, PCI DSS, and related baselines — formatted as evidence for auditors.
We compare the scan's externally visible checks with current guidance and transparent security benchmarks. A good result is useful evidence that your public domain follows many of the same technical expectations; it is not certification, a compliance decision or a replacement for internal testing.
Comparative analysis last reviewed: 17 August 2026
Close means broad coverage of the same external surface. Strong overlap means many shared checks within a narrower specialist benchmark. Supporting evidence means selected requirements only, and Limited means only a small externally visible part of a much broader framework.
This list is a commitment, not a description of current limitations.
Anything deeper — and there's very little we'd ever add — would be separate, clearly labelled, opt-in, and gated behind verified proof that you own the domain. It would never be quietly added to the standard scan.
External observation cannot see everything, and we would rather say so.
We don't assess your internal network, your endpoints, your staff practices, or anything behind a login. A scan is one view of your risk, best used alongside internal reviews and penetration testing.
That nothing malicious was visible to our checks at the time of the scan. No verdict from any tool, ours included, is a guarantee. Use results to inform judgement, not to replace it.
MyDomainRisk is built and operated by Huro Data Technologies Ltd., a UK company — self-sustaining on subscriptions, not venture-funded, with no advertising, no data sales, and no resale of your information. Data handling is documented in our privacy policy and GDPR commitment; security researchers can find our vulnerability disclosure policy here.
The checker on our homepage runs genuine checks with no account, and shows exactly the kind of findings a full scan produces. Or browse a sample report first to see how a full scan reads.