What is publicly visible about this organisation's systems, as an outsider would find it.
As passive, plus one ordinary web request and TLS handshake per host. No authorisation on record. Passive sources only.
10 findings across 2 discovered names, of which 1 currently resolves.
5 new, 3 resolved, 1 changed, 4 unchanged.
Rotate this DKIM key to at least 2048-bit RSA or to Ed25519.
Publish an MTA-STS policy so sending servers require TLS when delivering to you.
https://www.rfc-editor.org/rfc/rfc8461
Once legitimate senders are confirmed, change '~all' to '-all'.
https://www.rfc-editor.org/rfc/rfc7208
Informational. A change to the scripts your site serves will be reported as a change. If no release explains it, take the site offline and investigate: this is how wallet-draining code reaches users.
https://securityalliance.org/our-work/seal-911
Informational. A change to where vulnerability reports are sent will be reported as a change.
Publish a DMARC record at _dmarc.<domain>. Start with 'p=none' and a reporting address, review the reports, then move to 'p=quarantine' and 'p=reject'.
https://www.rfc-editor.org/rfc/rfc7489
Publish an SPF record listing the services allowed to send mail for this domain, ending in '-all'. If the domain sends no mail, publish 'v=spf1 -all'.
https://www.rfc-editor.org/rfc/rfc7208
Publish CAA records naming the certificate authorities allowed to issue for this domain. This limits mis-issuance if a DNS or web account is compromised.
https://www.rfc-editor.org/rfc/rfc8659
| Change | Kind | Name | Detail |
|---|---|---|---|
| Changed | Domain | perimeterwatch.org | resolves: no, cname: none → resolves: yes, cname: none, web: yes, https: yes, tls: yes |
Hostnames found in public records, and how your DNS is protected.
Enable DNSSEC at your DNS provider and publish the DS record at your registrar. It protects against forged DNS answers.
https://frameworks.securityalliance.org/
Your domain has a lock at the registrar but none at the registry. A registry lock needs a person to confirm any change by a separate channel, which stops a hijack even when the registrar account is taken over. Ask your registrar whether it offers one.
https://frameworks.securityalliance.org/
All nameservers belong to one provider. Consider whether a second DNS provider is worth the added resilience.
Informational. A change of registrar or nameservers will be reported as a change. If you did not make it, treat it as a hijack in progress.
https://securityalliance.org/our-work/seal-911
Informational. A change to where vulnerability reports are sent will be reported as a change.
| Name | Points to | Addresses | Note |
|---|---|---|---|
| perimeterwatch.org | 162.55.43.236, 2a01:4f8:c016:78c3::1 | Perimeterwatch: see what the internet sees of your organisation |
1 further name appears in public records but no longer resolves. The full list is in the JSON report.
Whether someone can send mail that appears to come from your domain.
Rotate this DKIM key to at least 2048-bit RSA or to Ed25519.
Publish an MTA-STS policy so sending servers require TLS when delivering to you.
https://www.rfc-editor.org/rfc/rfc8461
Once legitimate senders are confirmed, change '~all' to '-all'.
https://www.rfc-editor.org/rfc/rfc7208
Registered domains that resemble yours. These were found through DNS and certificate records only. None of them was contacted.
No issues found.
DNS records pointing at something that no longer exists. These are candidates found from DNS alone: confirm each before acting.
No issues found.
Credentials found in public repositories. Values are never stored or shown in full. Found credentials were not tested.
Not checked in this scan: no github org configured for this target.
Work email addresses that appear in known data breaches. Only the breach name, date and kinds of data are shown. No passwords are collected or stored.
Not checked in this scan: requires a verified domain.
Multisig and contract control, source code organisation, and hiring disclosures.
Not checked in this scan: no contracts configured for this target.
What you ship and how it reaches users: the scripts your site serves, the packages you publish, and how your repositories are protected.
Informational. A change to the scripts your site serves will be reported as a change. If no release explains it, take the site offline and investigate: this is how wallet-draining code reaches users.
https://securityalliance.org/our-work/seal-911
Informational. These are the outside services your domain relies on. Each is a party that could take your site or mail down, or be used to attack you. A service being added or removed will be reported as a change.
Results of active checks, run only with authorisation.
Not checked in this scan: active module, not requested.
What ran, what did not, and why. A check that did not run says nothing about that area.
| Check | Depth | Result | Detail | Time |
|---|---|---|---|---|
| Breach exposure breaches |
passive | skipped | Requires a verified domain. To fix: pwatch verify init perimeterwatch.org | 0.0s |
| Subdomain discovery subdomains |
passive | ok |
names: 2, from_crt.sh: 0, from_subfinder: 1 |
19.5s |
| DNS resolution and hygiene dns_resolve |
passive | ok |
names: 2, resolving: 1, dns_errors: 0 |
0.1s |
| Public storage buckets bucket_exposure |
active | skipped | Active module, not requested. To fix: add --active to the scan | 0.0s |
| Who controls your contracts contract_control |
passive | skipped | No contracts configured for this target. To fix: pwatch target add perimeterwatch.org --help | 0.0s |
| Domain registration domain_registration |
passive | ok |
nameservers: 2, findings: 2 |
1.0s |
| Email spoofing protection email_posture |
passive | ok |
checks: 3, failed_checks: 0 |
169.4s |
| Web servers http_probe |
probe | ok |
contacted: 1, answered: 1 |
0.9s |
| TLS certificates tls_certs |
probe | ok |
contacted: 1, certificates: 1 |
0.2s |
| Website scripts and security headers frontend |
probe | ok |
Any script that is added, removed or altered is reported as a change. Many sites put a build code in file names (for example app.3f9a1c.js), so every release changes this list. That is expected: match each reported change to a release. A change that no release explains needs investigating at once. Text after a question mark in a script address is ignored, because it is often only there to refresh caches. Scripts written into the page itself are compared by content, so a page that writes a different value into a script on every visit will be reported as changed at every scan. Only the front page of each host was read. Scripts loaded by other pages, or added by another script after the page loads, are not seen. hosts: 1, pages_read: 1, scripts_fetched: 0 |
0.0s |
| Outside services you rely on dependencies |
passive | ok |
services: 2, sources_read: 6, sources_missing: 0 |
0.0s |
| DNSSEC signing quality dnssec_quality |
passive | ok |
lookups: 4 |
0.0s |
| ENS names ens_names |
passive | skipped | No ens names configured for this target. To fix: pwatch target add perimeterwatch.org --help | 0.0s |
| Pointers to your website content frontend_pointers |
passive | ok |
ens_contenthashes: 0, dnslink_records: 0, hostnames_checked: 2 |
0.0s |
| GitHub organisation github_org |
passive | skipped | No github org configured for this target. To fix: pwatch target add perimeterwatch.org --help | 0.0s |
| Secrets in public code github_secrets |
passive | skipped | No github org configured for this target. To fix: pwatch target add perimeterwatch.org --help | 0.0s |
| Technology named in job postings jobs_stack |
passive | skipped | No job board configured for this target. To fix: pwatch target add perimeterwatch.org --help | 0.0s |
| Lookalike domains lookalikes |
passive | partial |
11892 variations exist. The first 6000 were checked. 672 variations could not be checked because of DNS errors. variations_checked: 6000, registered: 0, mail_capable: 0, certificate_matches: 0 |
169.6s |
| Nameserver health nameserver_health |
probe | ok |
nameservers_asked: 2, queries_sent: 13 |
170.6s |
| Exposures and misconfigurations nuclei_safe |
active | skipped | Active module, not requested. To fix: add --active to the scan | 0.0s |
| Domains trusted by your SPF record spf_chain |
passive | ok |
domains_checked: 1, lookups: 1, missing: 0 |
149.8s |
| Servers behind your content delivery network origin_exposure |
passive | ok |
No host was found to be served through a content delivery network, so there is no hidden server to look for. behind_cdn: 0, candidates: 0, exposed: 0 |
0.0s |
| Published packages packages |
passive | skipped | No npm or PyPI packages configured for this target. To fix: pwatch target add perimeterwatch.org --help | 0.0s |
| Lookalike domains reported for phishing phishing_lists |
passive | partial |
The lookalike search was incomplete, so some lookalike domains were not compared with the blocklists. blocklists_read: 3, blocklists_failed: 0, blocklist_names: 548226, lookalikes_compared: 0, lookalikes_listed: 0, name_matches: 0, own_names_listed: 0 |
0.2s |
| Open ports ports |
active | skipped | Active module, not requested. To fix: add --active to the scan | 0.0s |
| Repository safeguards repo_scorecard |
passive | skipped | No github org configured for this target. To fix: pwatch target add perimeterwatch.org --help | 0.0s |
| Safe modules, guard and code safe_modules |
passive | skipped | No safes configured for this target. To fix: pwatch target add perimeterwatch.org --help | 0.0s |
| Safe multisig signers safe_multisig |
passive | skipped | No safes configured for this target. To fix: pwatch target add perimeterwatch.org --help | 0.0s |
| Where to report security problems security_contact |
probe | ok |
requests: 1 |
0.3s |
| SSH server settings ssh_audit |
active | skipped | Active module, not requested. To fix: add --active to the scan | 0.0s |
| Dangling DNS records takeover |
passive | ok |
aliases_checked: 0, candidates: 0 |
0.0s |
| TLS versions and cipher suites tls_config |
active | skipped | Active module, not requested. To fix: add --active to the scan | 0.0s |
| Sensitive addresses in web archives web_archive |
passive | ok |
addresses_read: 0, sensitive_addresses: 0, groups: 0 |
0.0s |
| DNS zone transfer zone_transfer |
active | skipped | Active module, not requested. To fix: add --active to the scan | 0.0s |
This report lists what can be seen from outside. It is not a penetration test or an audit, and it gives no overall score. An area with no findings is not proven safe.