How Blindspot Measures Public Exposure
You enter a domain. We read what is already published about it, confirm what we find, and turn it into a grade and a prioritized list.
We never log in, test a credential, install software, or enter a private network.
- No Login
- No Software
- No Network Access
- Public Records Only
- DNS recordspublic
- Certificate transparency logspublic
- Public web responsespublic
- Domain registrationpublic
- Breach and infostealer datasetslicensed
- Your systemsnever touched
We Observe the Door. We Do Not Open It.
Blindspot is passive by design and is not a penetration test. It reads what is already served publicly. If a check would need a password, credential testing, exploitation, or access to a private system, it is outside what Blindspot does.
That boundary is not evidence that a business is secure. It defines the question this scan answers, which is what someone can already discover from outside.
The Eight Things Blindspot Checks
Eight categories run on every scan. This is the production list, so a category appears here only because the scanner actually runs it.
Can someone send email that looks like it came from you?
Email authentication
Reported when: SPF, DKIM or DMARC is missing, or the policy does not ask receiving servers to refuse forged mail.
Is the plumbing behind your domain set up correctly?
DNS hygiene
Reported when: A supported record such as MX, DNSSEC or CAA is absent or cannot do its job.
Is your site about to start warning visitors it is unsafe?
Certificates
Reported when: A certificate is expired or close to expiry, or a supported public protection is absent.
Are staff addresses at your domain already in public breach data?
Breach exposure
Reported when: Addresses at the domain appear in a supported dataset. Counts and dates only; never a password.
Is your site sending visitor information somewhere it should not?
Website privacy
Reported when: A served page discloses tracking or technology worth knowing about.
Has someone registered a domain one character from yours?
Lookalike domains
Reported when: A variant is registered and configured to receive mail, which is preparation rather than coincidence.
What of yours is reachable from the open internet?
Public discovery
Reported when: A host is publicly reachable that a business would not expect to be.
Could your domain be lost or taken?
Registration
Reported when: Registration is close to expiry, or transfer protection is absent.
Three Outcomes, and No Fourth
Pass
The check completed and the failing condition was not found.
It does not mean the business is secure. It means this one thing was fine when we looked.
Finding
The check completed and confirmed a condition that meets the published rule.
Every finding shows the evidence behind it and what it takes to fix.
Unavailable
The check could not produce a reliable answer.
Never converted into a pass. It is named in your result, excluded from the score, and it lowers confidence.
Confirmation is specific to each check. DNS results are compared across independent resolvers before anything is reported. Certificate and public-host signals have to hold on retrieval. A dataset result must meet the rule documented for that source. There is deliberately no blanket claim that every finding is confirmed twice, because the rules genuinely differ by check and a single sentence covering all of them would be false.
How the Grade Is Calculated
Every scan starts at 100. Each confirmed finding takes points off by how much it matters. What is left is your grade. Nothing is weighted secretly.
Points removed per finding
- 30Critical
- 18High
- 8Medium
- 3Low
- 0Informational
What is left is your grade
- A90 and above
- B80 to 89
- C70 to 79
- D60 to 69
- FBelow 60
The score never goes below zero, and no single finding caps the grade on its own. Several findings in one category each take their own points, which is why a domain with three medium email problems can score lower than one with a single high one. The grade summarizes the findings. It does not replace reading them.
What Blindspot Never Does
This is the boundary, and it is not a policy we could quietly relax. It is what makes it possible to scan any business, for free, without asking anyone first.
No Passwords
We never ask for one, never test one, and never show you one we found.
No Login
Nothing is accessed. There is no account to create and nothing to authorize.
No Software
Nothing is installed on your machines or your network.
No Network Access
We never touch your systems. Every check reads a record that is already public.
Evidence, Data Handling, and Limits
Findings show the evidence behind them, redacted where showing it in full would cause harm. A password recovered from a breach dataset is never displayed, stored for you, or tested against anything. Exposure results are reported as counts and dates.
What this scan cannot tell you: whether your internal network is secure, whether your staff would fall for a phishing message, whether you are compliant with any framework, or whether a finding has already been exploited. A clean grade means the supported public checks found nothing, and nothing more than that.
If you believe a finding is wrong, write to us and we will recheck it at no cost. A finding that cannot be reproduced is removed.
Method last reviewed 2026-08-24 against the production scanner. Changes to the check register, weights, or grade bands are reflected here in the same release.
Now See It on Your Own Domain
The method above, run against your business. Thirty seconds, no signup, no access required.
We only read public records. We never touch your computers and we never ask for a password.