Eexposed.

rrdlabs.online presents

Know the second your attack surface changes

Most security tools give you a report and then forget about you. Exposed takes a fresh snapshot of your public footprint every day, diffs it against the last one, and tells you the moment something appears that was not there yesterday.

https://

Passive and read-only. We read public CT logs, public DNS, the TLS handshake and page headers. We never brute-force, scan ports or send payloads. You must own or be authorised to monitor the domain.

No account neededRead-only, passiveFree for registered charities
exposed — passive scan
$ exposed scan acme.example
  ✓ certificate transparency      14 hostnames discovered
  ✓ dns records                  A AAAA MX NS TXT CAA
  ✓ tls                          TLS1.3 · valid 214d
  ✓ response headers              5 of 6 recommended present
  ! dangling_cname                staging.internal.acme.example
  ! cert_hostname_mismatch        www.acme.example
  ! missing_dmarc                 no v=dmarc1 in TXT

  3 findings · 14 hostnames · 4 sources · 1.9s
  passive only: no port scanning, no payloads, no brute force

  $ _

The gap

A scan is a photograph. Exposure is a film.

A one-time audit tells you what was true on the day. It cannot tell you that someone registered a subdomain in your name six hours ago, that your mail records changed, or that your certificate quietly stopped being renewed.

Those are the changes that actually get exploited, and they are the ones nobody looks at. Watching is the product. The first scan is free so you can see what you have been missing.

Certificate Transparency

Every certificate a CA has ever issued is public. We read those logs to find hostnames on your domain that nobody remembers adding.

Public DNS

Records, and the ones that point at providers you stopped using. A CNAME to a dead host is a takeover waiting to happen.

TLS handshake

Expiry, issuer, hostname match, and whether the server still shakes hands with TLS 1.0 from 2014.

Response headers

HSTS, CSP, framing, sniffing, referrers, plus plaintext login forms and server version banners.

How it works

Three steps. Fifteen seconds to the first one.

01

Scan it once, free

No account. Enter a domain and get a real report in about fifteen seconds. This is the part most tools charge for.

02

We keep watching

Every day we take a fresh snapshot of all of it and diff it against the last one. New hostnames, changed records, expiring certificates.

03

You get told first

The moment something appears that was not there yesterday, an alert lands in your inbox. That is the whole product.

What it looks for

Every check, in the open

No black box and no marketing adjectives. These are the actual rules, with the actual severities, and the reasoning behind each one.

Dangling CNAME

Subdomain takeover

critical

Certificate expired

Browser warnings

critical

Expired nameservers

Domain is dead

critical

TLS 1.0 accepted

Downgrade attacks

high

Cert hostname mismatch

Name warning

high

Self-signed cert

Unverifiable TLS

high

HTTP not forced

Plaintext traffic

high

Login form over HTTP

Credentials in clear

high

Missing HSTS

Stripped to HTTP

medium

New subdomain

Someone else added it

medium

New DNS record

Unauthorised change

medium

No DMARC

Email spoofing

medium

Missing CSP

XSS exposure

low

Version disclosure

Free recon

low

No CAA record

Cert impersonation

info

Example output

Plain language, not a wall of jargon

Every finding explains what an attacker could actually do about it, and what to change. No CVE parade, no risk score out of ten telling you nothing.

And the one you cannot act on is the whole point of a subscription: new subdomain appeared while you slept.

  • Dangling CNAME — subdomain takeover risk

    critical

    staging.internal.acme.example points at acme-tickets.herokuapp.com, but that target does not resolve to any address. Anyone able to claim that Heroku app can silently take over the subdomain.

    staging.internal.acme.example

  • Certificate does not match this hostname

    high

    The certificate served by www.acme.example failed verification (ERR_TLS_CERT_ALTNAME_INVALID). Visitors get a name-mismatch warning.

    www.acme.example

  • New subdomain appeared

    medium

    grafana.acme.example showed up in Certificate Transparency logs since the last scan. If you did not add it, someone else registered it on your domain.

    grafana.acme.example

Pricing

The first scan is free. Watching is the subscription.

Free

One domain, one scan

Free

  • One domain monitored
  • One full exposure report
  • Passive scan: DNS, TLS, headers, subdomains
  • No account required
Scan a domain

Most people pick this

Solo

Keep watching, every day

$19/mo

  • Up to 5 domains
  • Daily re-scans
  • Email alert the moment something changes
  • 90 days of scan history
  • New subdomain detection
  • Self-serve cancel
Start watching

Pro

Everything, monitored continuously

$49/mo

  • Unlimited domains
  • Daily scans plus on-demand
  • Alert on every new finding, not just new hosts
  • Full history, no 90-day cut-off
  • Outbound webhook for alerts
  • Priority: reply from the founder
Start watching

Registered charities and nonprofits monitor for free. Apply here.

For nonprofits

If you are a registered charity, this is free.

No budget for security tooling is not a moral failing. Claim it with your registration number and we will switch your monitoring on at no cost, permanently.

Claim free monitoring

Find out what you are already exposing.

Free, no account, about fifteen seconds.

https://

Passive and read-only. We read public CT logs, public DNS, the TLS handshake and page headers. We never brute-force, scan ports or send payloads. You must own or be authorised to monitor the domain.