Rosebud Cloud Solutions
Home
How We Work
Case Studies
About
Sign in
Rosebud Cloud Solutions

Engineering the next generation of cloud experiences. We blend technical gravitas with aesthetic precision to build systems that scale.

Solutions

  • Azure Landing Zones
  • Cloud Security
  • DevSecOps
  • Cloud Optimisation
  • Managed Cloud
  • Advisory & Consulting
  • Free Security Check

Company

  • How We Work
  • About Us
  • Meet the Team
  • Insights
  • Reports
  • FAQ
  • Contact

Connect

  • LinkedIn
  • Instagram

© 2024–2026 Rosebud Cloud Solutions Ltd

Company No. 14500087  ·  VAT No. 439 921 563  ·  Registered in England & Wales

Privacy Policy
External Security

Free Domain Security Check

The free front door to External Security — our outside-in protection for everything attackers can see. Run a free scan that checks over 40 points across your email security, web and TLS, external exposure, attack surface, and brand. No install, no sign-up, no access to your systems.

In seconds. Nothing to install, no access to your systems.

40+
Individual checks
6
Coverage areas
100%
External & passive
None
Sign-up to scan
The full picture

Over 40 checks, across six fronts

Most free scanners look at SPF and a TLS certificate and call it a day. This one runs the same comprehensive passive assessment we use in our paid audits, on every scan, entirely from the outside. Here is exactly what it looks at.

mark_email_read

Email Security

Can anyone send mail as you, and does yours get delivered?

  • checkSPF record & policy
  • checkSPF lookup budget
  • checkSPF hygiene
  • checkDKIM signatures & selectors
  • checkDKIM key strength
  • checkDMARC policy & enforcement
  • checkDMARC reporting
  • checkMTA-STS policy
  • checkMTA-STS enforcement mode
  • checkTLS-RPT reporting
  • checkBIMI verified logo
  • checkARC forwarding integrity
  • checkReverse DNS (FCrDNS)
  • checkMail-server IP reputation
  • checkMail delivery resilience
  • checkDNSSEC
public

Web & TLS

Is your website configured safely?

  • checkTLS version & ciphers
  • checkCertificate health & expiry
  • checkTLS hardening grade
  • checkHSTS
  • checkContent-Security-Policy
  • checkClickjacking protection
  • checkMIME-sniffing protection
  • checkReferrer-Policy
  • checkPermissions-Policy
  • checkCookie security flags
  • checkMixed content
  • checkServer version disclosure
  • checkSecurity-header depth
  • checkCAA records
travel_explore

External Exposure

What can an attacker discover about you?

  • checkSubdomain discovery
  • checkSubdomain-takeover exposure
  • checkCertificate Transparency exposure
  • checkDNS zone-transfer (AXFR)
  • checkWildcard DNS
  • checkNameserver diversity
  • checkDomain expiry
  • checkRegistrar transfer lock
  • checksecurity.txt disclosure policy
badge

Additional context

Extra intelligence we surface, for context.

  • checkMicrosoft 365 footprint
  • checkStaff email-address pattern
  • checkHostname naming exposure
  • checkCompliance framework alignment
fingerprint

Identity & Brand

Who could impersonate you?

  • checkLook-alike domains
  • checkMail-enabled lookalike abuse
shield

Attack Surface

Can your infrastructure absorb an attack?

  • checkDDoS scrubbing coverage

The scanner runs entirely from outside your network, the same view an attacker has. It reads publicly available DNS records and public-facing services only. It never sends test emails, never logs in to anything, and never touches your internal systems.

Why it matters

What the big findings mean for you

mail

Email authentication: SPF, DKIM and DMARC

SPF tells receiving mail servers which systems are authorised to send email for your domain. DKIM adds a cryptographic signature so recipients can verify messages have not been tampered with. DMARC ties these together and tells receiving servers what to do when a message fails. Without an enforced DMARC policy, your domain can be spoofed and used in phishing attacks against your own customers, suppliers, and staff.

public

Web and TLS health

The scan checks your TLS certificate validity and configuration and the presence of key HTTP security headers such as HSTS and Content-Security-Policy. Weak or expired certificates and missing headers are among the most common findings in external security assessments, and they directly affect whether browsers and customers treat your site as safe.

travel_explore

External exposure

Subdomains created for old projects and never decommissioned stay visible to attackers. The scan maps the subdomains and services associated with your domain to show what is publicly facing. Forgotten DNS records pointing at decommissioned infrastructure are a well-documented source of subdomain takeover vulnerabilities.

Who it is for

Built for UK businesses, free to run

More than four in ten UK businesses identified a cyber attack or breach in the past year, and phishing remains by far the most common type (UK Government Cyber Security Breaches Survey 2025/26). Misconfigured or missing SPF, DKIM and DMARC records mean your domain can be used to phish your own customers and suppliers without your knowledge.

The check is designed for IT managers, operations leads, and business owners who want a quick external view before a board update, a tender submission, a Cyber Essentials assessment, or a conversation with a security partner. The results are written in plain English, so you do not need to be technical to act on them.

Common questions

Domain security, answered

What is DMARC and why does my business need it?

add

DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receiving mail servers what to do when an email claims to come from your domain but fails authentication. Without an enforced DMARC policy, criminals can send convincing phishing emails to your customers, suppliers, and staff that appear to come from you. The NCSC recommends DMARC as a baseline control for UK organisations.

What is the difference between SPF, DKIM and DMARC?

add

SPF lists which mail servers are allowed to send email for your domain. DKIM adds a cryptographic signature to outgoing messages so recipients can verify they have not been tampered with. DMARC ties the two together and sets a policy telling receiving servers to quarantine or reject messages that fail. All three working together is the standard the NCSC recommends. For the full picture, read our plain-English guide to SPF, DKIM and DMARC.

Will running this scan affect my website or email?

add

No. The scan is passive and external. It reads publicly available DNS records and checks your public-facing web services, the same information anyone on the internet can already see. It does not send test emails, log in to anything, or touch your internal systems.

What happens to the information I enter?

add

The scan uses only publicly available DNS and web data. We keep the scan results so we can generate your report, and if you ask us to email it to you we store your address to send it and to follow up once. We never sell or share your details with third parties. See our privacy policy for full detail.

What do I get in the emailed report?

add

The instant result shows your overall score, rating, and how many issues were found. Your emailed report, sent as a private link, breaks down every finding with a severity rating and explains in plain English what each one means, across email security, web and TLS, external exposure, attack surface, and brand. The step-by-step fix for every issue comes with the £50 full report, downloadable as a PDF.

Found something you want fixed?

Get the £50 full report and you'll have the exact fix for every finding, prioritised and ready to action. A free scan commits you to nothing.

Specifically worried about email impersonation and DMARC? Our Managed DMARC service walks your domain safely to full enforcement, done for you.