Perimeterwatch Sign in

Open source · Non-profit · Beta

See what the internet sees of you. Hear when it changes.

Perimeterwatch watches the public attack surface of a crypto organisation: its domains, mail, certificates, public code, packages, job postings, multisigs and contracts. It scans only domains whose owners asked, and it is free.

Start monitoring a domain See a sample report Read the source on GitHub

Opt-in only · Proof of domain control · No scores · Apache-2.0

33checks running today
104kinds of finding, each with a fix
3depths, chosen by you
0scores, grades or public listings

How it works

One DNS record. Then it watches.

  1. Prove control of a domain

    Add one TXT record where your DNS is managed. Nothing is scanned before it is in place, and it is checked again before every scan.

  2. Choose how deep to look

    Passive reads public records and connects to none of your hosts. Probe makes a few ordinary requests per host, as a visitor would. Active checks open ports and known misconfigurations, read-only.

  3. Read the report, then hear about changes

    The first report is the map. After that, scans repeat on a schedule and you are told what is new, what was fixed and what changed, by email, Slack, Discord or Telegram.

dns and terminal
; 1. prove control
_perimeterwatch-verify.acme-protocol.xyz.
  300  IN  TXT  "pw-verify=3kP9vX…"

# 2. scan, from the site or your own machine
$ pwatch scan acme-protocol.xyz --active
  ok  email_posture      2 findings
  ok  safe_modules       1 finding
  ok  lookalikes         3 findings
  ok  ports              0 findings

# 3. what changed
acme-protocol.xyz: 2 high  3 medium  6 low
Since the last scan: 2 new, 1 resolved, 1 changed.

What it checks today

33 checks, from your DNS to your multisig.

Each check says what it contacts and what it found. None of them gives your organisation a score or a grade.

Passive: public records onlyProbe: ordinary requests to your hostsActive: ports and misconfigurations

Domains and DNS

  • DNS resolution and hygiene
  • DNSSEC signing quality
  • Dangling DNS records
  • Domain registration
  • Subdomain discovery
  • Nameserver health

Servers and certificates

  • Sensitive addresses in web archives
  • Servers behind your content delivery network
  • TLS certificates
  • Web servers
  • Where to report security problems

Email and lookalikes

  • Domains trusted by your SPF record
  • Email spoofing protection
  • Lookalike domains
  • Lookalike domains reported for phishing

Public code and packages

  • GitHub organisation
  • Outside services you rely on
  • Pointers to your website content
  • Published packages
  • Repository safeguards
  • Secrets in public code
  • Technology named in job postings
  • Website scripts and security headers

Web3

  • ENS names
  • Safe modules, guard and code
  • Safe multisig signers
  • Who controls your contracts

Reachable services

  • DNS zone transfer
  • Exposures and misconfigurations
  • Open ports
  • Public storage buckets
  • SSH server settings
  • TLS versions and cipher suites

Every check, what it contacts and every finding it can raise →

Safeguards

What it never does.

A service that maps weak points has to be safe to say yes to. These rules are enforced in the code and covered by tests, not only promised.

Never scans without proof

No domain is scanned until its owner proves control by DNS record. The proof is checked again before every scan.

Never guesses

It reads names from public records. It does not guess hostnames, passwords or paths, and sends read-only requests.

Never strays

It refuses private addresses and any host whose operator asked to be left alone. Beyond your own hosts it asks only your nameservers and the storage buckets your DNS points at.

Never keeps a secret

A leaked credential is reported by where it is, not by what it is. No password is stored or shown.

Never hands your name to a list

Blocklists are downloaded whole and matched here. Your domain is not sent to a lookup service.

Never mixes organisations

One organisation cannot see anything about another. Sensitive fields are encrypted at rest, and views of them are logged.

Roadmap

Free now. Funding decides how far it goes.

Perimeterwatch is applying for grant funding. The service is free during the beta, and the funding is what keeps it free for small teams. What waits is what costs money: data, outside review and time.

Live In the beta today

  • 33 checks at three depthsDomains, mail, certificates, code, packages, job postings, multisigs, contracts.
  • Change alertsEmail, Slack, Discord and Telegram, with no sensitive detail in the message.
  • Scheduled scansDaily or weekly, with proof of control checked each time.
  • Reports to keepHTML and JSON, with a published schema.
  • Audit logWho looked at what, and when.

Coming soon First, with funding

  • Breach and malware-log alertsStaff addresses seen in a breach or in infostealer logs. Built and switched off: the data costs money. The planned source is Have I Been Pwned Pro 1, at $379 a month for up to 50 domains. The alternative is the Intelligence X Identity Portal, at €10,000 a year. Published prices, read on 30 September 2026.
  • Independent security reviewAn outside firm tests the service itself, and the report is published with the fixes. Estimated at $20,000; no quote yet.
  • Lawyer-reviewed terms and privacy policyThe drafts are public now. Estimated at $6,000; no quote yet.
  • Backups and monitoringSo that organisations can rely on it.

Coming soon Then

  • Build pipeline auditWorkflows in your public repositories that could run an outsider's code with your publishing secrets.
  • Timelock watchOperations queued on your timelock, shortened delays and new role holders, before they execute.
  • Evidence for othersA report format that security ratings and certification efforts can read, with your consent.
  • More voicesA second maintainer, and a non-profit to hold the service.

For operators of scanned hosts

Found us in your logs?

Then the owner of the domain being scanned asked for the scan. Every web request carries a User-Agent that names this site and an address for complaints.

To have a host left alone, write to abuse@perimeterwatch.org. The host goes on a list that no scan will contact. No explanation is needed. The opt-out page has the details.

To report a vulnerability in Perimeterwatch itself, see the disclosure policy or security.txt.

how to recognise the scanner
# User-Agent of every web request
perimeterwatch/0.1.0 (+https://perimeterwatch.org; abuse: abuse@perimeterwatch.org)

# scans come from these addresses only
162.55.43.236
2a01:4f8:c016:78c3::1

Add your first domain in five minutes.

Sign in with a work email address, add a DNS record, and read your first report. Or run the same engine yourself: it is one command-line tool.

Start monitoring a domain Run it yourself