Posture summary
Email authentication
SPF ✓ DMARC none DKIM ✓ DNSSEC ✗TLS / certificate
TLS TLSv1.3 35d to expiryInternet exposure
3 open ports 1 KEVBreach metadata
0 public breachesDomain & hosting
9 public hostnames registered 2017 AS20473 · AS-VULTR - The Constant Company, LLC no blocklist hitsPublic attack surface (9 hostnames in Certificate Transparency)
Hostnames this organization published in public TLS certificates. Passive OSINT — nothing was scanned; a wildcard certificate is in use, so the real footprint may be larger.
The hostname inventory — which forgotten hosts exist and where — is part of the complete audit for this domain.
Lookalike domains (2 registered of 72 checked)
Registered permutations of this domain. Existence is a fact, not an accusation — ownership and intent are not assessed. Those able to receive mail are the ones usable for invoice fraud and phishing.
| Domain | Type | Mail-capable |
|---|---|---|
| smssme.com | omission | yes |
| sms-me.com | omission | no |
Recommendations
-
highEnforce DMARC
No enforcing DMARC policy was observed. Publish a DMARC record and move to p=quarantine then p=reject to reduce spoofing.
-
mediumEnable DNSSEC
DNSSEC signing was not detected for this domain.
-
highClose risky exposed services
1 risky service port(s) appear internet-exposed. Restrict them behind a firewall or VPN.
-
criticalPatch known-exploited vulnerabilities
1 known-exploited vulnerability(ies) may affect exposed services. Prioritize patching.
-
criticalPatch what already has a public exploit
1 vulnerability(ies) reported on this host have working exploit code published (Exploit-DB, Metasploit, Nuclei or a public PoC). Exploitation needs no development effort — patch these first.
-
highMonitor lookalike domains
1 registered lookalike domain(s) can receive mail, which is what makes them usable for invoice fraud and credential phishing. Monitor them and consider defensive registrations.
Refresh this report
Re-run a live analysis or generate a full downloadable audit.
Open live reportAll information is aggregated from public sources for awareness only and does not constitute an accusation or a security assessment. No personal data or credentials are published.