How to Assess a Website's External Attack Surface
The order to work in, the signals that matter, and the four things an outside view genuinely cannot reach.
Guides
Practical guides on external website security: assessing an attack surface, SPF, DKIM and DMARC, security headers, and reporting for agencies.
Four guides on external website security, written for people who have to act on the answer rather than for people who already run the tooling. Each one states what the method can and cannot see, uses configuration examples you can apply directly, and links to the product page for the part that is automated.
They are written and published by Soryvex Security Ltd.. Nothing here is research: there are no survey figures, no benchmark data and no statistics from anyone else's study, because the only measurements available are the ones the product takes on the domain it assesses.
The order to work in, the signals that matter, and the four things an outside view genuinely cannot reach.
The three records, the order to change them, what alignment means, and the mistakes that leave you with a policy you think is enforced.
Header by header: what it prevents, what breaks, and the four mistakes that leave a policy that looks right and does nothing.
The report shape that gets acted on, the authorisation question for client sites, and a fix-verification loop that holds up in an audit.
The free plan assesses one domain, four times a month, and every finding arrives with its evidence.
Read-only. No credentials used. Nothing installed on your site.