Domains and DNS
- DNS resolution and hygiene
- DNSSEC signing quality
- Dangling DNS records
- Domain registration
- Subdomain discovery
- Nameserver health
Open source · Non-profit · Beta
Perimeterwatch watches the public attack surface of a crypto organisation: its domains, mail, certificates, public code, packages, job postings, multisigs and contracts. It scans only domains whose owners asked, and it is free.
Start monitoring a domain See a sample report Read the source on GitHub
Opt-in only · Proof of domain control · No scores · Apache-2.0
web3.safe.module_enabled
frontend.scripts
lookalike.reported_phishing
email.dmarc.missing
How it works
Add one TXT record where your DNS is managed. Nothing is scanned before it is in place, and it is checked again before every scan.
Passive reads public records and connects to none of your hosts. Probe makes a few ordinary requests per host, as a visitor would. Active checks open ports and known misconfigurations, read-only.
The first report is the map. After that, scans repeat on a schedule and you are told what is new, what was fixed and what changed, by email, Slack, Discord or Telegram.
; 1. prove control _perimeterwatch-verify.acme-protocol.xyz. 300 IN TXT "pw-verify=3kP9vX…" # 2. scan, from the site or your own machine $ pwatch scan acme-protocol.xyz --active ok email_posture 2 findings ok safe_modules 1 finding ok lookalikes 3 findings ok ports 0 findings # 3. what changed acme-protocol.xyz: 2 high 3 medium 6 low Since the last scan: 2 new, 1 resolved, 1 changed.
What it checks today
Each check says what it contacts and what it found. None of them gives your organisation a score or a grade.
Passive: public records onlyProbe: ordinary requests to your hostsActive: ports and misconfigurations
Every check, what it contacts and every finding it can raise →
Safeguards
A service that maps weak points has to be safe to say yes to. These rules are enforced in the code and covered by tests, not only promised.
No domain is scanned until its owner proves control by DNS record. The proof is checked again before every scan.
It reads names from public records. It does not guess hostnames, passwords or paths, and sends read-only requests.
It refuses private addresses and any host whose operator asked to be left alone. Beyond your own hosts it asks only your nameservers and the storage buckets your DNS points at.
A leaked credential is reported by where it is, not by what it is. No password is stored or shown.
Blocklists are downloaded whole and matched here. Your domain is not sent to a lookup service.
One organisation cannot see anything about another. Sensitive fields are encrypted at rest, and views of them are logged.
Roadmap
Perimeterwatch is applying for grant funding. The service is free during the beta, and the funding is what keeps it free for small teams. What waits is what costs money: data, outside review and time.
For operators of scanned hosts
Then the owner of the domain being scanned asked for the scan. Every web request carries a User-Agent that names this site and an address for complaints.
To have a host left alone, write to abuse@perimeterwatch.org. The host goes on a list that no scan will contact. No explanation is needed. The opt-out page has the details.
To report a vulnerability in Perimeterwatch itself, see the disclosure policy or security.txt.
# User-Agent of every web request perimeterwatch/0.1.0 (+https://perimeterwatch.org; abuse: abuse@perimeterwatch.org) # scans come from these addresses only 162.55.43.236 2a01:4f8:c016:78c3::1
Sign in with a work email address, add a DNS record, and read your first report. Or run the same engine yourself: it is one command-line tool.