External attack surface

What your attacker sees first

WebScan finds the public face of your organisation — including the hosts nobody wrote down — and grades it against the published standards that define it. TLS, HTTP headers, cookies, DNS, exposed services, content and infrastructure. No tenant, no consent, no agent: it sees what an anonymous visitor sees.

In one line: the outside-in half of your posture — free to run, priced only when you keep it.

Why it matters

The outside is the only half of your posture an attacker can assess without credentials — and the only half a prospective customer can check before they sign anything. It is also the half that usually gets looked at once a year, by a different tool, and filed as a PDF that is wrong within the month.

Nothing here is exotic. Weak TLS, a missing CAA record, a cookie without Secure — every one is a known standard, publicly specified, and trivially checkable from outside. Which is exactly why being wrong about them is hard to explain afterwards.

What it does

  • Finds what you did not list — subdomain and asset discovery turns up the hosts nobody remembered. Two sources, and they are not equally prompt: the names on the certificate your site already served are read on the first scan, while certificate transparency builds up as certificates are logged. The natural partner to the CAA check — CAA says who may issue, transparency logs say who did — with the coverage caveat on the limits page, which you should read before relying on it.
  • Transport and certificates — TLS versions and cipher suites, the certificate chain and its expiry, HSTS, and a client handshake simulation that answers the question a version list cannot: which browsers and clients can actually connect.
  • The HTTP surface — security headers, cookie flags, the redirect chain. Small configuration facts that are individually dull and collectively the difference between a contained mistake and a session hijack.
  • DNS hygiene — CAA, DNSSEC, nameserver and record hygiene. Who is allowed to issue a certificate for your name, and can anyone tell if the answer changed.
  • Content and infrastructure — exposed paths and files, a published security.txt, open ports and services reachable from outside, and what your server volunteers about itself.
  • Modern protocol readiness — IPv6 and the current transport stack, because reachability is part of posture and the answer is rarely what people assume.
  • Every check cites its standard — the RFC or specification is printed next to the finding, which is what turns "the scanner says so" into a change request someone approves.
  • Free on every tenant — one URL at a time, fire and forget. Every check, at no cost and with no expiry date. You pay when you want the answer kept.

How it runs, and why free is free

Each scan is a short-lived Azure Function. Nothing is installed, nothing runs inside your tenant, and on the free tier nothing is written down when the scan finishes — which is precisely what makes it free to give away. It is also why free scans are on demand only: nothing schedules itself, so a free scan costs what it costs and then stops.

The free tier runs one URL at a time and keeps nothing, which is what lets it stay free indefinitely rather than becoming a trial. It is also authenticated — an anonymous scanner aimed at domains the caller does not own is reconnaissance run from our addresses, and that ends with our egress ranges on a blocklist and somebody else's abuse report.

What it is not, today

Not a penetration test. WebScan grades configuration against published standards; as it stands it does not attempt exploitation and cannot see anything behind a login. Active testing and authenticated scanning are on the roadmap — until they ship, this paragraph is the accurate description.

What will not change: it never writes — not to your DNS, not to your web server. DNS write-back belongs to MailTrust, which also owns SPF, DKIM and DMARC. Those are mail authentication rather than web surface, and they will not be duplicated here.

Inside WebScan

What’s in the product

The screen you will actually work in.

A grade you can take apart

Not a letter and a list of red crosses. Every failure carries the standard it breaks, why that matters, the fix, and — if you are not going to fix it — somewhere to say so.

A WebScan result: a score of 54 rated D, with 12 passed, 10 failed, 5 not assessed
                      and 4 not applicable, listing a missing security.txt, missing CAA records and weak
                      TLS protocols, each with why it matters, a fix, and a waiver request.

Four states, because three would be a lie

Passed, failed, not assessed and not applicable are kept apart. A check that could not run is never folded into either column — a grade that hides its own gaps is worse than no grade.

  1. A grade, and what it is made of. The four counts sit next to the score, so a low number can be read rather than argued with.
  2. Every failure cites the RFC. The standard is the reason. That is what turns a scanner result into a change someone will actually approve.
  3. Why it matters, then the fix, then a waiver. If you are not going to fix it, say so on the record — the check stays on screen either way, and the waiver expires.

Scan my site, free

Domain replaced in the screenshot. The findings are the real ones.

Capability and what you get from it

CapabilityWhat it means for you
Unauthenticated, from outsideNo consent to arrange; a licensed site can be one you do not own yet
Standard references on every checkThe finding is a specification, not an opinion
Four result states, kept apartAn unreadable check never becomes a quiet pass
Scheduled scans and retained historyProof the configuration held between audits
Waivers with mandatory expiryAccepting a risk is recorded and re-surfaces, not buried
Control tags into CompliancePortalThe external surface becomes evidence with no second integration
Fleet view across domains and tenantsRank a client book by public exposure in one screen

Objections, answered straight

"Free tools already grade my TLS."

They do, well. Then they forget, and the result lives in a browser tab. WebScan's difference is not the check — it is that the result is kept, tagged to a control, and sits next to the rest of your posture instead of in someone's bookmarks.

"We had a penetration test in March."

A penetration test is a date. Certificates expire, headers get dropped in a deploy, a new subdomain appears. This is the part of that report that should have been a schedule.

"Is the free tier crippled?"

Not in what it checks — the check set is identical and so is the result. It is capped in reach: one URL at a time, and it forgets. Nothing is held back to make the paid version look cleverer; what you buy is the memory.

"Can it break my site?"

It requests pages and reads DNS the way any visitor does. No exploitation, no fuzzing, no load. If a scan could take your site down, an ordinary crawler already would have. Should active testing ever ship — it is on the roadmap — it will be a separate, explicitly consented mode, never something the default scan starts doing.

Pick a domain and find out

Your own, free, three times a day. You will see exactly what the licensed version would have recorded — the difference is what happens to it afterwards.

Free and Pro

A scan you do not keep cannot prove anything

The free tier is a complete scanner, not a teaser — every check, every result, on one site three times a day. What it does not do is remember, and remembering is the whole of the paid product. Two licences: scan it, or keep it.

Free

On every tenant, automatically

Every check, every result — one URL at a time, fire and forget. Nothing is withheld from the check set; what it does not do is remember. When you close the page it is gone: no history, no evidence, nothing watching between scans.

Discovery is not part of free, and not as a lever: it is an inventory of what appeared and when, so it needs a saved site to attach to and a yesterday to compare against. Free has neither.

Good for: checking a site whenever you want to know. Proving a fix landed. Deciding whether Pro is worth it on evidence rather than on a demo.

Pro

Per monitored site

The site becomes something we remember, and something that re-scans itself on a cadence you set. Runs are retained, history plots, findings and waivers exist, the audit trail records who decided what, and control tags carry into CompliancePortal.

It also starts the daily watches: a certificate expiring in thirty days is a fact that arrives on a clock, not on a scan. Those read stored data and send nothing to your site — which is why they need a saved site to exist at all, and why free cannot have them.

Discovery is included and never billed. Hostnames found under a site you already pay for cost nothing and are listed, not scanned — the name, whether it still resolves, and where it pointed. Turning one into a monitored site is your decision and a button; only then is it scanned, and only then does it count.

One paid licence, not a ladder

Keeping a scan and scheduling it used to be separate tiers. That sold a distinction nobody actually makes: a saved site nobody re-scans is a stale record, and a schedule that keeps nothing is a cron job with no output. Pro grants both, and there is nothing between them worth charging for.

Named, not shipped

What WebScan does not check yet

Everything below is something a competing tool does today and WebScan does not. It is written here rather than discovered during an evaluation. None of it is built, none of it is dated, and none of it is included in a licence you buy today.

Correlating what it already finds

WebScan reports the software a server discloses and the endpoints it can see. It does not yet join those facts to anything.

  • Known-CVE correlation against disclosed software versions
  • API endpoint discovery

Both extend a check that already runs. CVE correlation also brings a vulnerability database to keep current, which is a maintenance commitment rather than a feature.

Actively testing, not just grading

A change in kind, not degree, and the one to be most careful about — it brings false positives, scan windows and permission-to-test paperwork with it.

  • Active vulnerability testing — injection, cross-site scripting and the rest
  • Authenticated scanning, behind a login

If these arrive they will be an explicit, separately consented mode. The free tier stays what it is now: unauthenticated, non-intrusive, and safe to point at anything.

Signals from beyond the site itself

Things that say something about exposure without being a property of your web configuration.

  • Leaked credential and breach exposure
  • Lookalike and typosquatted domains
  • IP and domain reputation, blocklist presence
  • Malware and defacement detection on served content
  • Third-party portfolio scoring — rating the vendors you depend on

The last would take WebScan into third-party risk management, a different buyer and a different product. It is listed because it was asked for, not because it is settled.

One thing that is not a gap

Comparison tables will show WebScan missing SPF, DKIM and DMARC. That is deliberate and permanent: mail authentication is MailTrust, on the same domains, feeding the same findings store. It is not absent from the platform — only from this product.