Perimeterwatch · Exposure report

perimeterwatch.org

What is publicly visible about this organisation's systems, as an outsider would find it.

Scanned
30 September 2026, 15:06 UTC
Depth
Probe
Authorisation
None on record
Scan reference
710736fd

As passive, plus one ordinary web request and TLS handshake per host. No authorisation on record. Passive sources only.

Summary

10 findings across 2 discovered names, of which 1 currently resolves.

0critical
0high
1medium
4low
5info

Baseline checks

Do these first

  1. medium DKIM key 'resend' for perimeterwatch.org is only 1024 bits
    Rotate this DKIM key to at least 2048-bit RSA or to Ed25519.
  2. low perimeterwatch.org is not signed with DNSSEC
    Enable DNSSEC at your DNS provider and publish the DS record at your registrar. It protects against forged DNS answers.
  3. low perimeterwatch.org shows a registrar lock but no lock at the registry
    Your domain has a lock at the registrar but none at the registry. A registry lock needs a person to confirm any change by a separate channel, which stops a hijack even when the registrar account is taken over. Ask your registrar whether it offers one.
  4. low perimeterwatch.org has no MTA-STS policy
    Publish an MTA-STS policy so sending servers require TLS when delivering to you.
  5. low The SPF record for perimeterwatch.org only soft-fails unlisted senders
    Once legitimate senders are confirmed, change '~all' to '-all'.

Changes since the previous scan

5 new, 3 resolved, 1 changed, 4 unchanged.

New 5

medium DKIM key 'resend' for perimeterwatch.org is only 1024 bits
Affects
perimeterwatch.org
Certainty
Confirmed
Selector
resend
Key type
rsa
Bits
1024
What to do

Rotate this DKIM key to at least 2048-bit RSA or to Ed25519.

low perimeterwatch.org has no MTA-STS policy
Affects
perimeterwatch.org
Certainty
Confirmed
What to do

Publish an MTA-STS policy so sending servers require TLS when delivering to you.

Reference

https://www.rfc-editor.org/rfc/rfc8461

low The SPF record for perimeterwatch.org only soft-fails unlisted senders
Affects
perimeterwatch.org
Certainty
Confirmed
Record
v=spf1 include:_spf.mx.cloudflare.net ~all
What to do

Once legitimate senders are confirmed, change '~all' to '-all'.

Reference

https://www.rfc-editor.org/rfc/rfc7208

info perimeterwatch.org serves 0 scripts
Affects
perimeterwatch.org
Certainty
Confirmed
Page
https://perimeterwatch.org/
Own script files
0
Scripts written into the page
0
Scripts from other sites
none
Addresses that load nothing
0
Base address set by page
Note
Any script that is added, removed or altered is reported as a change. Many sites put a build code in file names (for example app.3f9a1c.js), so every release changes this list. That is expected: match each reported change to a release. A change that no release explains needs investigating at once. Text after a question mark in a script address is ignored, because it is often only there to refresh caches. Scripts written into the page itself are compared by content, so a page that writes a different value into a script on every visit will be reported as changed at every scan.
What to do

Informational. A change to the scripts your site serves will be reported as a change. If no release explains it, take the site offline and investigate: this is how wallet-draining code reaches users.

Reference

https://securityalliance.org/our-work/seal-911

info perimeterwatch.org publishes where to report security problems
Affects
perimeterwatch.org
Certainty
Confirmed
Address
https://perimeterwatch.org/.well-known/security.txt
Location used
/.well-known/security.txt
Contacts in order of preference
mailto:security@perimeterwatch.org
Policy
https://perimeterwatch.org/legal/vulnerability-disclosure
Canonical
https://perimeterwatch.org/.well-known/security.txt
Expires
2027-03-01
Encryption key
none
Preferred languages
en
Acknowledgments
none
Lines that could not be read
0
What to do

Informational. A change to where vulnerability reports are sent will be reported as a change.

Changed 1

lowperimeterwatch.org relies on 2 outside services
Affects
perimeterwatch.org
Before
services: role: dns, service: Cloudflare
Now
services: service: Cloudflare, role: dns, service: Cloudflare, role: mail, service: Cloudflare, role: mail_sending, service: Let's Encrypt, role: certificates

Resolved 3

high perimeterwatch.org has no DMARC record, so spoofed mail is not rejected
Affects
perimeterwatch.org
Certainty
Confirmed
What to do

Publish a DMARC record at _dmarc.<domain>. Start with 'p=none' and a reporting address, review the reports, then move to 'p=quarantine' and 'p=reject'.

Reference

https://www.rfc-editor.org/rfc/rfc7489

medium perimeterwatch.org has no SPF record
Affects
perimeterwatch.org
Certainty
Confirmed
What to do

Publish an SPF record listing the services allowed to send mail for this domain, ending in '-all'. If the domain sends no mail, publish 'v=spf1 -all'.

Reference

https://www.rfc-editor.org/rfc/rfc7208

low perimeterwatch.org has no CAA record
Affects
perimeterwatch.org
Certainty
Confirmed
What to do

Publish CAA records naming the certificate authorities allowed to issue for this domain. This limits mis-issuance if a DNS or web account is compromised.

Reference

https://www.rfc-editor.org/rfc/rfc8659

Assets

ChangeKindNameDetail
ChangedDomainperimeterwatch.orgresolves: no, cname: none → resolves: yes, cname: none, web: yes, https: yes, tls: yes

Attack surface

Hostnames found in public records, and how your DNS is protected.

low perimeterwatch.org is not signed with DNSSEC
Affects
perimeterwatch.org
Certainty
Confirmed
What to do

Enable DNSSEC at your DNS provider and publish the DS record at your registrar. It protects against forged DNS answers.

Reference

https://frameworks.securityalliance.org/

low perimeterwatch.org shows a registrar lock but no lock at the registry
Affects
perimeterwatch.org
Certainty
Likely
Status
add period, client transfer prohibited
How decided
No status set by the registry is published. A registry lock shows as statuses such as 'server transfer prohibited'.
What to do

Your domain has a lock at the registrar but none at the registry. A registry lock needs a person to confirm any change by a separate channel, which stops a hijack even when the registrar account is taken over. Ask your registrar whether it offers one.

Reference

https://frameworks.securityalliance.org/

info All nameservers for perimeterwatch.org are with one provider
Affects
perimeterwatch.org
Certainty
Confirmed
Nameservers
felicity.ns.cloudflare.com, sonia.ns.cloudflare.com
What to do

All nameservers belong to one provider. Consider whether a second DNS provider is worth the added resilience.

info perimeterwatch.org is registered through Cloudflare, Inc.
Affects
perimeterwatch.org
Certainty
Confirmed
Registrar
Cloudflare, Inc.
Nameservers
felicity.ns.cloudflare.com, sonia.ns.cloudflare.com
Status
add period, client transfer prohibited
Registrar iana id
1910
Registered on
2026-09-29
Expires on
2027-09-29
What to do

Informational. A change of registrar or nameservers will be reported as a change. If you did not make it, treat it as a hijack in progress.

Reference

https://securityalliance.org/our-work/seal-911

info perimeterwatch.org publishes where to report security problems
Affects
perimeterwatch.org
Certainty
Confirmed
Address
https://perimeterwatch.org/.well-known/security.txt
Location used
/.well-known/security.txt
Contacts in order of preference
mailto:security@perimeterwatch.org
Policy
https://perimeterwatch.org/legal/vulnerability-disclosure
Canonical
https://perimeterwatch.org/.well-known/security.txt
Expires
2027-03-01
Encryption key
none
Preferred languages
en
Acknowledgments
none
Lines that could not be read
0
What to do

Informational. A change to where vulnerability reports are sent will be reported as a change.

Hosts that resolve 1

NamePoints toAddressesNote
perimeterwatch.org 162.55.43.236, 2a01:4f8:c016:78c3::1 Perimeterwatch: see what the internet sees of your organisation

1 further name appears in public records but no longer resolves. The full list is in the JSON report.

Email security

Whether someone can send mail that appears to come from your domain.

Mail servers
route3.mx.cloudflare.net, route2.mx.cloudflare.net, route1.mx.cloudflare.net
SPF record
v=spf1 include:_spf.mx.cloudflare.net ~all
DMARC record
v=DMARC1; p=quarantine; rua=mailto:dmarc@perimeterwatch.org
DKIM selectors found
resend
MTA-STS
missing
medium DKIM key 'resend' for perimeterwatch.org is only 1024 bits
Affects
perimeterwatch.org
Certainty
Confirmed
Selector
resend
Key type
rsa
Bits
1024
What to do

Rotate this DKIM key to at least 2048-bit RSA or to Ed25519.

low perimeterwatch.org has no MTA-STS policy
Affects
perimeterwatch.org
Certainty
Confirmed
What to do

Publish an MTA-STS policy so sending servers require TLS when delivering to you.

Reference

https://www.rfc-editor.org/rfc/rfc8461

low The SPF record for perimeterwatch.org only soft-fails unlisted senders
Affects
perimeterwatch.org
Certainty
Confirmed
Record
v=spf1 include:_spf.mx.cloudflare.net ~all
What to do

Once legitimate senders are confirmed, change '~all' to '-all'.

Reference

https://www.rfc-editor.org/rfc/rfc7208

Lookalike domains

Registered domains that resemble yours. These were found through DNS and certificate records only. None of them was contacted.

No issues found.

Dangling DNS and takeover candidates

DNS records pointing at something that no longer exists. These are candidates found from DNS alone: confirm each before acting.

No issues found.

Leaked secrets

Credentials found in public repositories. Values are never stored or shown in full. Found credentials were not tested.

Not checked in this scan: no github org configured for this target.

Breach exposure

Work email addresses that appear in known data breaches. Only the breach name, date and kinds of data are shown. No passwords are collected or stored.

Not checked in this scan: requires a verified domain.

Web3 and organisation

Multisig and contract control, source code organisation, and hiring disclosures.

Not checked in this scan: no contracts configured for this target.

Code, packages and frontend

What you ship and how it reaches users: the scripts your site serves, the packages you publish, and how your repositories are protected.

info perimeterwatch.org serves 0 scripts
Affects
perimeterwatch.org
Certainty
Confirmed
Page
https://perimeterwatch.org/
Own script files
0
Scripts written into the page
0
Scripts from other sites
none
Addresses that load nothing
0
Base address set by page
Note
Any script that is added, removed or altered is reported as a change. Many sites put a build code in file names (for example app.3f9a1c.js), so every release changes this list. That is expected: match each reported change to a release. A change that no release explains needs investigating at once. Text after a question mark in a script address is ignored, because it is often only there to refresh caches. Scripts written into the page itself are compared by content, so a page that writes a different value into a script on every visit will be reported as changed at every scan.
What to do

Informational. A change to the scripts your site serves will be reported as a change. If no release explains it, take the site offline and investigate: this is how wallet-draining code reaches users.

Reference

https://securityalliance.org/our-work/seal-911

info perimeterwatch.org relies on 2 outside services
Affects
perimeterwatch.org
Certainty
Confirmed
Dns
service: Cloudflare, revealed_by: nameserver felicity.ns.cloudflare.com in the registration record, nameserver sonia.ns.cloudflare.com in the registration record, nameserver felicity.ns.cloudflare.com in your NS records, nameserver sonia.ns.cloudflare.com in your NS records
Mail
service: Cloudflare, revealed_by: mail server route3.mx.cloudflare.net in your MX records, mail server route2.mx.cloudflare.net in your MX records, mail server route1.mx.cloudflare.net in your MX records
Mail sending
service: Cloudflare, revealed_by: include:_spf.mx.cloudflare.net in your SPF record
Certificates
service: Let's Encrypt, revealed_by: issued the certificate served by perimeterwatch.org
Read from
DNS resolution, the domain registration check, the email check, the web server check, the certificate check, the website script check
Not read this time
none
Note
Each service listed is an outside party your domain depends on. A service that appears or disappears between scans is reported as a change. Match each change to something your team did. One that nobody can explain needs looking into.
What to do

Informational. These are the outside services your domain relies on. Each is a party that could take your site or mail down, or be used to attack you. A service being added or removed will be reported as a change.

Exposed services and misconfigurations

Results of active checks, run only with authorisation.

Not checked in this scan: active module, not requested.

Coverage and limitations

What ran, what did not, and why. A check that did not run says nothing about that area.

CheckDepthResultDetailTime
Breach exposure
breaches
passive skipped Requires a verified domain. To fix: pwatch verify init perimeterwatch.org 0.0s
Subdomain discovery
subdomains
passive ok
names: 2, from_crt.sh: 0, from_subfinder: 1
19.5s
DNS resolution and hygiene
dns_resolve
passive ok
names: 2, resolving: 1, dns_errors: 0
0.1s
Public storage buckets
bucket_exposure
active skipped Active module, not requested. To fix: add --active to the scan 0.0s
Who controls your contracts
contract_control
passive skipped No contracts configured for this target. To fix: pwatch target add perimeterwatch.org --help 0.0s
Domain registration
domain_registration
passive ok
nameservers: 2, findings: 2
1.0s
Email spoofing protection
email_posture
passive ok
checks: 3, failed_checks: 0
169.4s
Web servers
http_probe
probe ok
contacted: 1, answered: 1
0.9s
TLS certificates
tls_certs
probe ok
contacted: 1, certificates: 1
0.2s
Website scripts and security headers
frontend
probe ok
Any script that is added, removed or altered is reported as a change. Many sites put a build code in file names (for example app.3f9a1c.js), so every release changes this list. That is expected: match each reported change to a release. A change that no release explains needs investigating at once. Text after a question mark in a script address is ignored, because it is often only there to refresh caches. Scripts written into the page itself are compared by content, so a page that writes a different value into a script on every visit will be reported as changed at every scan.
Only the front page of each host was read. Scripts loaded by other pages, or added by another script after the page loads, are not seen.
hosts: 1, pages_read: 1, scripts_fetched: 0
0.0s
Outside services you rely on
dependencies
passive ok
services: 2, sources_read: 6, sources_missing: 0
0.0s
DNSSEC signing quality
dnssec_quality
passive ok
lookups: 4
0.0s
ENS names
ens_names
passive skipped No ens names configured for this target. To fix: pwatch target add perimeterwatch.org --help 0.0s
Pointers to your website content
frontend_pointers
passive ok
ens_contenthashes: 0, dnslink_records: 0, hostnames_checked: 2
0.0s
GitHub organisation
github_org
passive skipped No github org configured for this target. To fix: pwatch target add perimeterwatch.org --help 0.0s
Secrets in public code
github_secrets
passive skipped No github org configured for this target. To fix: pwatch target add perimeterwatch.org --help 0.0s
Technology named in job postings
jobs_stack
passive skipped No job board configured for this target. To fix: pwatch target add perimeterwatch.org --help 0.0s
Lookalike domains
lookalikes
passive partial
11892 variations exist. The first 6000 were checked.
672 variations could not be checked because of DNS errors.
variations_checked: 6000, registered: 0, mail_capable: 0, certificate_matches: 0
169.6s
Nameserver health
nameserver_health
probe ok
nameservers_asked: 2, queries_sent: 13
170.6s
Exposures and misconfigurations
nuclei_safe
active skipped Active module, not requested. To fix: add --active to the scan 0.0s
Domains trusted by your SPF record
spf_chain
passive ok
domains_checked: 1, lookups: 1, missing: 0
149.8s
Servers behind your content delivery network
origin_exposure
passive ok
No host was found to be served through a content delivery network, so there is no hidden server to look for.
behind_cdn: 0, candidates: 0, exposed: 0
0.0s
Published packages
packages
passive skipped No npm or PyPI packages configured for this target. To fix: pwatch target add perimeterwatch.org --help 0.0s
Lookalike domains reported for phishing
phishing_lists
passive partial
The lookalike search was incomplete, so some lookalike domains were not compared with the blocklists.
blocklists_read: 3, blocklists_failed: 0, blocklist_names: 548226, lookalikes_compared: 0, lookalikes_listed: 0, name_matches: 0, own_names_listed: 0
0.2s
Open ports
ports
active skipped Active module, not requested. To fix: add --active to the scan 0.0s
Repository safeguards
repo_scorecard
passive skipped No github org configured for this target. To fix: pwatch target add perimeterwatch.org --help 0.0s
Safe modules, guard and code
safe_modules
passive skipped No safes configured for this target. To fix: pwatch target add perimeterwatch.org --help 0.0s
Safe multisig signers
safe_multisig
passive skipped No safes configured for this target. To fix: pwatch target add perimeterwatch.org --help 0.0s
Where to report security problems
security_contact
probe ok
requests: 1
0.3s
SSH server settings
ssh_audit
active skipped Active module, not requested. To fix: add --active to the scan 0.0s
Dangling DNS records
takeover
passive ok
aliases_checked: 0, candidates: 0
0.0s
TLS versions and cipher suites
tls_config
active skipped Active module, not requested. To fix: add --active to the scan 0.0s
Sensitive addresses in web archives
web_archive
passive ok
addresses_read: 0, sensitive_addresses: 0, groups: 0
0.0s
DNS zone transfer
zone_transfer
active skipped Active module, not requested. To fix: add --active to the scan 0.0s

Method

Sources consulted
crt.sh (certificate transparency), data.iana.org (the list of registration record servers), each discovered host, one TLS handshake on port 443, each discovered host, one web request, each of your web hosts: the front page and the script files that host serves, one nameserver of the parent zone, one question, phish.co.za (Phishing.Database list of active phishing domains, MIT licence), polkadot.js.org (polkadot-js/phishing blocklist, Apache licence 2.0), public DNS, public DNS resolvers, public DNS resolvers (1.1.1.1, 8.8.8.8, 9.9.9.9), at most four lookups, raw.githubusercontent.com (MetaMask eth-phishing-detect blocklist, DBAD licence 1.2), subfinder passive sources, the domain's own nameservers, about five ordinary DNS questions each, the registry's public registration record server (RDAP), web.archive.org (Internet Archive Wayback Machine index), your Ethereum RPC endpoint, your own domain: one request for /.well-known/security.txt
Identified as
perimeterwatch/0.1.0 (+https://perimeterwatch.org)
Contact
https://perimeterwatch.org
Data kept for
90 days
Tool versions
httpx: 1.12.0, subfinder: 2.16.0, tlsx: 1.4.0
Tool
Perimeterwatch 0.1.0, report format 1.0

This report lists what can be seen from outside. It is not a penetration test or an audit, and it gives no overall score. An area with no findings is not proven safe.