Built for domain portfolios that changed hands too many times

Find exposed DNS before someone else claims it.

Indominate checks mail authentication, certificate authority scope, nameserver redundancy, and common provider-backed CNAMEs so inherited domains stop hiding production risk.

Signals

6

Setup

0 keys

Cadence

daily

Public DNS probe
live

Awaiting target

No scan loaded

Enter a domain to inspect public DNS controls. Results are generated from live DNS responses and do not require account access.

Checks: SPF / DMARC / MX / CAA / NS / CNAME exposure

Output: score, failing controls, remediation notes

No account keys

The MVP runs on public DNS first, so a team can prove value before wiring registrar and provider integrations.

Risk, not trivia

Each finding maps to an operational concern: spoofing, certificate issuance, DNS resilience, or takeover exposure.

Built to expand

The scanner is structured for scheduled monitors, provider auth, alerts, and paid reports without rewriting the core.