What a domain security assessment covers
An external domain assessment reads public configuration and reports what it found and what it could not check. This guide explains each scope and its limits.
What external means
An external assessment observes your domain from the public internet, as any outside party could. It queries public DNS, connects to the mail servers your MX records name, and requests your public website. It does not log in, install anything or run code on your systems.
That gives it a useful property and a hard limit. Because it sees what everyone else sees, its findings describe what is really exposed. Because it sees only that, it can say nothing about what happens inside your network or your accounts.
Scope: DNS
The DNS scope collects the domain's public records and runs checks on them, including SPF, DMARC and MX record analysis. It also looks at DNSSEC state. The question it answers is whether the records that other systems rely on are present, well-formed and consistent.
A crucial distinction applies here. If a resolver fails or times out, that is a failure to ask, not evidence that a record is missing. A good assessment reports the first as UNKNOWN. Only an authoritative answer that the domain does not exist (NXDOMAIN) ends the assessment, and even then the result says only that DNS has no such name, not that the domain is unregistered.
Scope: email authentication
SPF and DMARC are published as DNS records, so they can be read directly and judged. The assessment looks at whether they exist, parse correctly, and what policy they express. It treats a monitoring-only DMARC policy as different from an enforcing one, and it treats the permission to send DMARC reports to an external address as a separate question from the policy itself.
DKIM is different. A DKIM key lives under a selector chosen by the sender, and selectors cannot be listed from outside. An assessment can confirm a key for a selector it tests, but it cannot prove that no other selector exists, nor that your mail is signed.
Scope: SMTP
The SMTP scope connects to the hosts in your MX records and checks whether they respond and whether they offer encrypted transport with STARTTLS. If your MX is a null MX, meaning you declare you receive no mail, there is nothing to connect to and the result is NOT_APPLICABLE rather than a failure.
A successful SMTP greeting shows that a server is listening. It does not prove that a particular message will be accepted or delivered.
Scope: website
The website scope checks that HTTPS is available, inspects the certificate, follows redirects, and reads response headers such as HSTS, Content-Security-Policy and framing controls. These are browser-facing protections that you can verify from a single request.
If a CDN or reverse proxy answers, the result describes that edge, not your origin server, and it should be read that way.
Scope: lookalike domains
The phishing exposure scope generates variants of your domain name, such as character substitutions, and checks which resolve. The output is a list of candidates for a human to review. A resolving lookalike is not proof of abuse, and a non-resolving one is not proof of safety.
Scope: reputation
Reputation checks query blocklist providers, and they only run when a provider has been licensed and enabled on the server. If none is enabled, the check is reported as NOT CONFIGURED. This is not a clean result. It says that the source was not consulted, nothing more.
How long it takes and what happens on timeout
The scopes run at the same time, and each has its own time limit, from 20 seconds for reputation to 95 seconds for the DNS module. Most assessments complete well within two minutes. If a module exceeds its limit, it is stopped and its planned checks are recorded as UNKNOWN. A check that a module was expected to report but did not is also recorded as UNKNOWN, so coverage cannot be overstated.
How to use the results
Treat the assessment as the start of a conversation with your own configuration, not a verdict. Read the coverage statement first, because it tells you how much weight the rest deserves. A result that concluded nearly every planned check is a stronger statement than one that concluded half of them, even if the headline label is the same.
Then work from the top of the priorities list, which is ordered by impact rather than by protocol. A missing DMARC enforcement policy and an expired certificate are in different protocols but can be compared on what they expose, and the ordering reflects that. For each item, open the evidence to see exactly what was observed, which resolver or host answered, and at what time.
Finally, make a change and measure again. Because an assessment is a snapshot, the only way to know that a fix worked is to run the same assessment afterwards and compare. The history of earlier runs for the same domain is kept so that changes in DNS records can be compared between scans.
- Start with coverage, then posture, then priorities.
- Open the evidence before changing anything.
- Change one thing at a time and re-run.
- Keep the earlier result so that you can compare.
Choosing scopes
You can run every scope or only some. Running only the DNS scope is quicker and is useful while you are working on records. Running SMTP and website scopes matters when you have changed mail servers or certificates. The phishing and reputation scopes are best used periodically instead of after every change. A category that was not part of the selected scope is shown as not assessed, which is different from passing.
What an assessment does not test
It does not test internal systems, authenticated areas or application logic. It does not attempt exploitation, brute-forcing or denial of service. It does not match software versions to vulnerability databases. It cannot tell you whether a message will reach an inbox, and it cannot see behind a CDN. Treat it as one dependable view of your public surface, not as a full security audit.
Frequently asked questions
Why does the assessment say it could not conclude some checks?
Because the evidence was not reliable, for instance a server timed out. Those checks are marked UNKNOWN and count against coverage rather than being treated as passes.
Can it prove my DKIM is set up?
Only for selectors it can test. Selectors cannot be enumerated from outside, so absence of a found key is not proof that none exists.
Does it scan my internal network?
No. It observes public DNS, mail servers and websites only.
Written by DNS Tools editorial · Last updated 2026-10-09