Find exposed DNS before someone else claims it.
Indominate checks mail authentication, certificate authority scope, nameserver redundancy, and common provider-backed CNAMEs so inherited domains stop hiding production risk.
Signals
6
Setup
0 keys
Cadence
daily
Awaiting target
No scan loaded
Enter a domain to inspect public DNS controls. Results are generated from live DNS responses and do not require account access.
Checks: SPF / DMARC / MX / CAA / NS / CNAME exposure
Output: score, failing controls, remediation notes
No account keys
The MVP runs on public DNS first, so a team can prove value before wiring registrar and provider integrations.
Risk, not trivia
Each finding maps to an operational concern: spoofing, certificate issuance, DNS resilience, or takeover exposure.
Built to expand
The scanner is structured for scheduled monitors, provider auth, alerts, and paid reports without rewriting the core.