TLS & certificates
Catch expiring certs, weak protocols, untrusted chains, and mismatched hostnames before browsers start warning your customers.
See category detail →Free scans show a limited preview: TLS, headers, DNS, mail-auth, and edge context—enough to spot major issues without exposing paid-tier finding detail. Paid plans unlock full findings, monitoring, history length tied to your tier, and alerts.
No account needed · Results in ~15 seconds · Shareable report URL
What ExposureGrid checks
Open ports aren't the whole picture. ExposureGrid looks at the configuration drift attackers actually use, and the misconfigurations your customers will actually notice first.
Catch expiring certs, weak protocols, untrusted chains, and mismatched hostnames before browsers start warning your customers.
See category detail →Check HSTS, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and the rest against what browsers actually enforce today.
See category detail →Inspect Content-Security-Policy strictness, cross-origin behavior, and cookie hygiene (Secure, HttpOnly, SameSite).
See category detail →Check SPF, DKIM, DMARC alignment, MTA-STS, and DNS hygiene that attackers use for phishing and brand impersonation.
See category detail →Surface the CDN, hosting, and edge configuration signals that shape your real attack surface from the outside.
See category detail →Re-scan on a schedule and see when posture changes: new findings, fixed findings, and regressions over time.
See category detail →For verified managed scans, ExposureGrid inventories public hostnames tied to domains you proved you control.
See category detail →Signals for dangling SaaS delegation or empty provider banners—surfaced responsibly for teams that own DNS.
See category detail →Lightweight probes for risky public listings on domain-derived storage prefixes, without scraping files.
See category detail →For verified managed scans, passive checks highlight reachable API docs, consoles, metrics, and health endpoints without posting to APIs.
See category detail →First-party bundles are hashed and sampled for reachable source maps, internal URL hints, and redacted secret-like literals. Not part of anonymous public scans.
See category detail →Header and HTML signals describe disclosed frameworks or servers without claiming CVE exploitability.
See category detail →Verified-domain monitoring
Subscribed users can enable deeper exposure scanners for verified managed domains, including exposed service detection, dangerous file checks, and publicly reachable admin interface discovery. These checks are excluded from free public scans and only run when enabled for domains you control.
Identify risky public services such as RDP, SMB, Redis, databases, Elasticsearch, SSH, FTP, and alternate web ports before they become easy attacker entry points.
Read features →Detect accidentally exposed .env files, Git metadata, backups, SQL dumps, debug logs, phpinfo pages, and other sensitive web-accessible artifacts.
Read features →Find publicly reachable admin panels and management consoles such as WordPress login, phpMyAdmin, Jenkins, Grafana, Kibana, Portainer, and more, without attempting to log in.
Read features →Paid exposure modules require an active subscription or trial, domain verification, and explicit per-domain configuration. They are never part of the free public scan.
How it works
We're honest about what an external scan can see and what it can't. You get findings backed by evidence, not a vague risk score.
1. Submit a domain
Run a free public scan, or add a domain after signing in. ExposureGrid resolves the host and plans a non-invasive set of checks.
2. Run safe, external checks
We collect public evidence (TLS handshakes, response headers, DNS records, CSP and CORS behavior). No payloads, no fuzzing, no intrusive probing.
3. Review findings & evidence
Each finding includes a severity, plain-English context, the exact evidence we captured, and a remediation step you can hand to a developer.
4. Monitor for drift
Schedule re-scans and get notified when posture regresses, certificates approach expiry, or new issues appear.
Who it's for
ExposureGrid is opinionated about external posture so a small team doesn't have to figure it out from scratch.
Keep your customer-facing app, marketing site, and auth subdomains aligned with the security posture you tell customers you have.
Watch every site you operate from one place. Catch regressions across client portfolios before the customer does.
Get a credible outside-in view without hiring a security team. Clear findings, evidence, and fixes you can hand to a developer.
Pricing
Public scans are always free. Continuous monitoring starts at $29/mo. Every paid plan includes a 14-day free trial (1 domain, no credit card). Your plan's full domain count is available the moment you subscribe.
Free
$0
Manual scans for one domain with a limited preview of findings—ideal to try the product before upgrading.
No trial required. Sign in for managed Free workspace limits.
Starter
$29/mo
Weekly monitoring and alerts for a single production domain.
Trial monitors 1 domain.
Pro
$79/mo
Portfolio coverage with expanded scanners on every managed domain.
Trial monitors 1 domain. All 5 are available on subscribe.
Premium
$149/mo
Full external posture for larger teams—optional daily cadence and priority scans.
Trial monitors 1 domain. All 10 are available on subscribe.
Every plan ships with the same scanner coverage. Pick the plan that fits how many domains you'll monitor once your trial converts.
FAQ
Short answers on what we scan, how the beta works, and how scans stay safe.
See it now
Run a free public scan, or create an account to monitor every site you depend on.