Posture summary
Email authentication
SPF ✓ DMARC none DKIM ✗ DNSSEC ✗TLS / certificate
TLS TLSv1.3 97d to expiryInternet exposure
2 open ports 0 KEVBreach metadata
1 public breachesDomain & hosting
1513 public hostnames AS16276 · OVH OVH SAS no blocklist hitsPublic attack surface (1513 hostnames in Certificate Transparency)
Hostnames this organization published in public TLS certificates. Passive OSINT — nothing was scanned; a wildcard certificate is in use, so the real footprint may be larger.
The hostname inventory — which forgotten hosts exist and where — is part of the complete audit for this domain.
Lookalike domains (26 registered of 44 checked)
Registered permutations of this domain. Existence is a fact, not an accusation — ownership and intent are not assessed. Those able to receive mail are the ones usable for invoice fraud and phishing.
| Domain | Type | Mail-capable |
|---|---|---|
| ivh.com | keyboard | yes |
| lvh.com | keyboard | yes |
| mailovh.com | prefix | yes |
23 further registered lookalike(s), 19 of them able to receive mail. The full list, with mail capability for each, is part of the complete audit.
Recommendations
-
highEnforce DMARC
No enforcing DMARC policy was observed. Publish a DMARC record and move to p=quarantine then p=reject to reduce spoofing.
-
mediumEnable DKIM
No DKIM record was found on common selectors. Enable DKIM signing.
-
mediumEnable DNSSEC
DNSSEC signing was not detected for this domain.
-
highRotate credentials exposed in public breaches
Public breach records name this domain in 1 reported breach(es), covering approximately 452,899 accounts in total; the most recent is dated 2015-05-01. Passwords were among the reported data classes. Enforce a password reset for affected accounts and require MFA.
-
criticalReset credentials seen in infostealer logs
Public infostealer telemetry associates 6601 employee credential set(s) with this domain — passwords captured from infected devices, which bypass password policy and often session-hijack past MFA. The most recent dates from 2026-08-02. Most commonly RedLine. Force a reset for the affected services, invalidate active sessions, and check the devices themselves.
-
mediumReview third-party credential exposure
55 credential set(s) for third-party services used by this domain appear in the same telemetry. Supplier and SaaS accounts are a common lateral path.
-
mediumStrengthen password requirements
75% of the exposed employee passwords analysed rate as weak or very weak. Raise minimum length and screen new passwords against breach lists.
-
highMonitor lookalike domains
19 registered lookalike domain(s) can receive mail, which is what makes them usable for invoice fraud and credential phishing. Monitor them and consider defensive registrations.
-
highLookalike domains are actively phishing
3 URL(s) on registered lookalike domains are listed in public phishing feeds — impersonation that is already live, not merely possible. Report them to the registrar and hosting provider, and warn staff and customers.
-
mediumReview the public subdomain footprint
1513 hostnames for this domain appear in public Certificate Transparency logs. Retire forgotten hosts — stale subdomains are a common entry point and a takeover risk.
-
highGet a full security audit
Multiple exposures were detected. A professional audit can prioritize remediation.
Refresh this report
Re-run a live analysis or generate a full downloadable audit.
Open live reportAll information is aggregated from public sources for awareness only and does not constitute an accusation or a security assessment. No personal data or credentials are published.