Non-intrusive external scanning

How we scan: non-intrusive by design

We observe; we don't touch

Trusting a security tool means knowing exactly what it does — and what it will never do. This page is that contract, in plain English.

The short version.

Every check looks only at what a domain already shows the public internet. Nothing is installed, nothing is logged into, nothing is attacked. That is why a check needs no access, no agreement and no agent: it reads what is already published, causes no disruption, and changes nothing.

The principle

One rule decides what is in a scan and what is not.

Every MyDomainRisk check is a non-intrusive external observation. We look at what a domain already shows to the public internet — its DNS records, its certificates, the headers its website sends, what public threat-intelligence sources say about it. Website protocol checks complete a small, bounded set of TLS handshakes without sending application data. They do not enumerate ciphers or attempt exploitation. Collection records for DNSSEC, disclosure files and cloud storage distinguish completed, incomplete and unavailable checks; completed collection is not a security pass. Historical reports retain their original evidence. RPKI routing intelligence is currently unavailable. Published vulnerability intelligence adds context without sending additional probes to the target.

The same holds at portfolio scale

The question every MSP and multi-domain owner asks before turning on scheduled monitoring.

Nothing accumulates

Monitoring a whole portfolio is the same safe observation repeated. There is no cumulative load and nothing compounds across domains or across weeks.

No permission needed

A scheduled scan across hundreds of domains needs no agreement and no coordination with whoever runs them.

No awkward phone call

You will not knock a client's site over, trip their firewall alerting, or have to explain yourself to their IT provider afterwards.

A weekly scan puts no more load on any one domain than a search engine visiting the homepage.

What a scan looks at

Eight categories of publicly visible signal. All of it is information the domain already publishes.

1

Certificates & encryption

Certificate validity and expiry, plus bounded TLS 1.0–1.3 handshakes on website port 443 on every plan. Unavailable probes remain unverified; this does not enumerate ciphers or certify the configuration.

2

Email protection

Published email records, observed DKIM key structure, and MTA-STS policy syntax and mail-server matching. DNSSEC validation is reported separately from signing-record presence. Unavailable evidence remains unverified; these checks do not test actual message authentication.

3

Web security headers

The protective HTTP headers your site sends with every page.

4

Internet exposure

Published service and vulnerability observations, supplemented by bounded connection checks. Dated known-exploitation intelligence helps prioritise reported vulnerabilities without claiming compromise or changing the domain score.

5

Domain hygiene

Registration expiry, transfer locks and DNS configuration. Pro/MSP full scans automatically review up to 50 related hosts per scanned domain using public certificate records and bounded DNS/HTTPS checks. Daily monitoring skips that review. Discovery is incomplete and indicators need ownership review; they do not confirm takeover or change the main score.

6

Lookalike domains

Registered domains that imitate yours — the raw material of phishing against your customers and staff.

7

Threat intelligence

Whether your domain, infrastructure, or employee credentials appear in trusted public and commercial threat feeds.

8

Compliance surface

The externally verifiable subset of GDPR Article 32, PCI DSS, and related baselines — formatted as evidence for auditors.

What we publish, and what we don't. Findings are explained in plain English with practical fix steps — we tell you what we found and why it matters, not the internal mechanics of how results are weighted. Those stay private for the same reason a bank doesn't publish its fraud rules.

How a good result relates to recognised standards

We compare the scan's externally visible checks with current guidance and transparent security benchmarks. A good result is useful evidence that your public domain follows many of the same technical expectations; it is not certification, a compliance decision or a replacement for internal testing.

Comparative analysis last reviewed: 17 August 2026

Close means broad coverage of the same external surface. Strong overlap means many shared checks within a narrower specialist benchmark. Supporting evidence means selected requirements only, and Limited means only a small externally visible part of a much broader framework.

Shared ground
Broad coverage of the same externally visible domain and attack-surface concerns.
What remains outside the scan
NCSC also covers wider asset and supplier discovery. We assess the domains you choose, not a complete organisation-wide inventory.
Shared ground
TLS, security headers, DNSSEC, email authentication, CAA and security.txt.
What remains outside the scan
Internet.nl promotes modern internet standards and includes areas such as IPv6 and DANE. Its grade is not interchangeable with ours.
Shared ground
CSP, HSTS, clickjacking, content-type, referrer-policy and cookie safeguards.
What remains outside the scan
Observatory is a specialist HTTP-header benchmark and tests some cases our broader domain scan does not reproduce.
Shared ground
Certificate validity and trust, protocol versions, weak encryption and HTTPS transport.
What remains outside the scan
SSL Labs performs deeper specialist TLS grading. A MyDomainRisk result is not an SSL Labs grade.
Shared ground
Public service exposure, secure configuration and visible vulnerability or software-update risk.
What remains outside the scan
Endpoints, user access, malware protection, internal networks and the certification assessment are outside an external domain scan.
Shared ground
Public encryption, exposed services and externally visible vulnerability signals.
What remains outside the scan
PCI DSS requires wider cardholder-data-environment evidence. We are not an Approved Scanning Vendor and cannot establish compliance.
Shared ground
External asset review, secure configuration, vulnerability management and email authentication.
What remains outside the scan
Many CIS safeguards require internal inventory, processes, endpoint controls and authenticated scanning.
Shared ground
Secure communications and some browser-facing configuration controls.
What remains outside the scan
Application logic, authentication, authorisation, sessions and data handling require dedicated application testing.
Shared ground
Evidence for external asset awareness, protective configuration and continuous monitoring.
What remains outside the scan
Most Govern, Identify, Protect, Detect, Respond and Recover outcomes require organisation-wide evidence.
Shared ground
Evidence that selected internet-facing technical risks are identified and monitored.
What remains outside the scan
ISO 27001 is an organisation-wide management-system standard. A domain scan cannot assess its governance, people or audit requirements.

What we never do

This list is a commitment, not a description of current limitations.

  • No software installed on your systems — ever. There are no agents.
  • No credentials accepted, tested, or guessed. We never ask for passwords and never attempt a login.
  • No exploitation. We observe that a door exists; we never try the handle.
  • No payload delivery, fuzzing, or fake-attack traffic.
  • No brute-force discovery — subdomains come from public certificate-transparency logs, not guessing.
  • No intrusive crawling. We fetch the kinds of public pages any visitor or search engine already fetches.
  • Nothing in a scan requires the domain owner's systems to do anything they don't already do for every visitor on the internet.

Anything deeper — and there's very little we'd ever add — would be separate, clearly labelled, opt-in, and gated behind verified proof that you own the domain. It would never be quietly added to the standard scan.

Honesty about limits

External observation cannot see everything, and we would rather say so.

What a scan cannot see

We don't assess your internal network, your endpoints, your staff practices, or anything behind a login. A scan is one view of your risk, best used alongside internal reviews and penetration testing.

What a clean result means

That nothing malicious was visible to our checks at the time of the scan. No verdict from any tool, ours included, is a guarantee. Use results to inform judgement, not to replace it.

Who's behind it

MyDomainRisk is built and operated by Huro Data Technologies Ltd., a UK company — self-sustaining on subscriptions, not venture-funded, with no advertising, no data sales, and no resale of your information. Data handling is documented in our privacy policy and GDPR commitment; security researchers can find our vulnerability disclosure policy here.

The best proof is a real scan

The checker on our homepage runs genuine checks with no account, and shows exactly the kind of findings a full scan produces. Or browse a sample report first to see how a full scan reads.

In short: nothing in a scan requires a domain's systems to do anything they don't already do for every visitor on the internet.

Back to top