Reports

See the threats and defense gaps around your domains — including the ones you don't know you own.

Start free on a single domain. The Cross-Estate Domain Risk Report then walks certificate, mail and registration relationships to find the rest of your estate — and shows you the risk that only appears when you look across it.

Free single-domain report

Threat exposure and DNS defense analysis

A practical report showing external threat context, DNS defense weaknesses and remediation priorities for one domain.

What it contains

Threat exposure
DNS records
Email posture
Platforms
Vendors
Certificates
Infrastructure
Remediation

Report value

External threat exposure and DNS defense gaps, in one report.

The free report is not just a posture snapshot. It connects the platforms visible around one domain with threat activity targeting those platforms, then identifies the DNS and email weaknesses that affect defense and remediation priorities.

Threats targeting your platform footprint

Identify external threat activity around the platforms, providers and vendors visible from your domain's public records.

Detailed DNS defense analysis

We check the baseline controls every domain should enforce (SPF, DKIM, DMARC), and show where the advanced and gold-standard layers (MTA-STS, TLS reporting, CAA, DNSSEC, BIMI) are available to you — as a maturity path, not a list of failures.

Remediation priorities

Translate findings into clear actions, likely owners and practical remediation effort so teams know what to fix first.

The free report covers one domain. Most organizations own more than they think — that's the first thing the Cross-Estate report shows you.

Cross-Estate Domain Risk Report

You've seen what one domain looks like. This is what the estate looks like.

Declared

The domains you told us about

Strongly associated

High-confidence: you own these

Possible

Medium-confidence: review these

Defensive

Consider recovering or monitoring

Estate discovery

You declare the domains you know. Discovery walks certificate, mail and registration relationships to evidence the ones you don't — sorted into four confidence tiers (declared, strongly associated, possible, defensive) with the connection shown for every domain. No guesses; every finding carries its evidence.

Systemic risk

Certain risks only become visible when you assess the domain estate as a whole. This includes the degree of dependency on a single provider — and whether that provider is a hyperscale platform or a low‑cost registrar — the weaknesses that repeat across segments, the acquisitions operating below group standards, and the assets approaching expiry. The Cross‑Estate Report is designed to surface this systemic layer and give leadership a clear view of where structural risk sits.

What the report contains

Threat context, DNS analysis and remediation priorities.

The value is in the contents: what is exposed, what is weak, what is being targeted and what should be fixed first.

Single domain

Domain Risk Report

Platform-led threat exposure

Which visible platforms and providers are being used as lures, and which suspicious domains, certificates or DNS patterns are relevant to them?

Platform luresVendor footprintBrand termsCertificatesDNS changesEvidence

DNS and email defense analysis

Which DNS and email records create spoofing, trust, routing or configuration weaknesses that should be fixed?

Baseline: SPF · DKIM · DMARCAdvanced: MTA-STS · TLS reportingGold standard: CAA · DNSSEC · BIMIMX providers

Platform and vendor footprint

Which email platforms, cloud services, SaaS providers, CDNs, nameservers and hosting relationships are visible?

Email platformCloudCDNHostingNameserversSaaS signals

Subdomain and infrastructure view

Which public subdomains, CNAMEs, provider relationships and hosting patterns expose the operating footprint?

SubdomainsA/AAAACNAMEsHostingASNRelated infrastructure

Remediation effort and cost indicators

Which issues are high priority, who is likely to own them, and what level of effort should be expected?

Risk rankingEvidenceNext stepsOwnersEffort bandsMonitoring path

Technical remediation appendix

Current state, target state, paste-ready records, staged rollout.

Current stateTarget statePaste-ready recordsStaged rollout

Multi-domain

Cross-Estate Domain Risk Report

Estate discovery

Declared, strongly associated, possible, defensive. Every discovered domain carries its connection evidence: a shared certificate, a mail route, a registration record.

Concentration & accumulation

The share of your estate on each provider, weighted by provider resilience and exit friction. The biggest number is not always the biggest finding — the report says which is which.

Posture variance & correlated weakness

Which segments sit below the group standard, and what's wrong the same way everywhere. A weakness on one domain is a ticket; on half the estate it's a policy gap, and it gets fixed at policy level.

Operational calendar & exception register

What expires next, what's already lapsed, and a single prioritized list of what to act on, in order.

Remediation worksheet

An appendix your IT team executes: exact records per domain, staged where staging matters (DMARC before SPF hard-fail), grouped by the account that administers each zone so one team's work lands in one change window.

Report catalog

Start with one domain, then understand the estate.

The free report gives a useful single-domain analysis. Paid reports expand the scope to the domains an organization owns and expose recurring weaknesses, inconsistent controls and systemic risk.

 

Free Domain Health Report

A targeted, single‑domain health check designed for leaders who need fast, defensible visibility. You get platform‑led threat exposure, a DNS defense review, and clear first‑action remediation priorities — a concise snapshot of where risk sits and what should happen next.

Single domain · paid

Domain Risk Report

A full, single‑domain risk assessment built for executive and technical leadership. The report opens with an evidence‑backed executive core: threat exposure, defense posture, and the substantiation behind every claim — written for board‑level consumption. It’s paired with a technical remediation appendix engineered for operational teams: every finding mapped from current state to target state, with paste‑ready records and changes sequenced in the order they should be deployed. Ideal for evaluating your own assets, vendor domains, client environments, or acquisition targets.

From $495per report
Contact usSee pricing

Multi-domain · paid

Cross-Estate Domain Risk Report

An estate‑wide risk assessment that exposes what single‑domain reporting cannot. We map declared domains, surface undisclosed or unknown assets, and quantify systemic risks across the estate — concentration, posture variance, correlated weaknesses, and operational timing. The report concludes with an actionable worksheet grouped by the teams responsible for each zone, enabling CISOs and CTOs to align remediation with ownership and operational reality. Available in editions tailored for technical teams, insurance underwriting, and M&A due‑diligence.

 

Partner-branded reports

White‑label reporting for MSSPs, ESPs, and security service providers who need enterprise‑grade analysis under their own brand. Any report in the catalog can be delivered as a partner‑branded edition, providing defensible evidence, technical depth, and executive‑ready clarity — all presented with your identity and integrated into your client workflow. Designed to expand your security portfolio, strengthen renewals, and deliver higher‑value insights without increasing analyst load.

By agreement
Talk to us

Sample findings

The report explains threat context, defense gaps and what to fix next.

A useful report should not simply list records. It should explain the external threat context, the defense weakness, the likely owner and the next action.

Platform threat exposure

Which platforms and vendors are visible, and is suspicious infrastructure appearing around those lures?

DNS defense gaps

Which baseline controls (SPF, DKIM, DMARC) need enforcing first, and which advanced and gold-standard layers (MTA-STS, TLS reporting, CAA, DNSSEC, BIMI) are available next on the maturity path?

Mail platform alignment

Does the public DNS footprint match the expected email platform and sender configuration?

Systemic portfolio risk

For paid reports, are the same weaknesses repeated across many domains, brands, subsidiaries or suppliers?

Remediation plan

What should be fixed first, who is likely to own it, and what level of effort or cost should be expected?

Discovery evidence

You declared 9 domains. Discovery evidenced 24 — including one expired acquisition name available for anyone to register.

Concentration weighting

64% of the estate sits on one commodity registrar with no transfer locks — while the 79% certificate-authority concentration is a config change to leave. The report ranks which concentration is the finding.

Where reports lead

A report should create the next security action.

The free report gives the single-domain baseline. Paid reports add estate-wide coverage, systemic risk analysis and recurring reporting across the domains an organization owns.

Alerts

Move priority brands, domains or platforms into live alerting for platform abuse, brand impersonation and suspicious infrastructure.

Estate monitoring

A report is the map on the day it runs. Under monitoring, discovery re-walks the estate every run — new domains join automatically, candidates queue for your confirmation, and the grade trend shows whether remediation is landing. The live feed covers what happens between runs.

Cloud data shares

Join report findings with analytical datasets for hunting, enrichment, trend analysis and marketplace delivery.

Partner services

Use reports as a customer-facing motion for MSSPs, ESPs, consultancies and managed-service providers.

Next step

View the sample, then get your own report.

The sample examples show the report anatomy. The free report applies the same structure to one domain using current Datazag intelligence.

See a sample Cross-Estate report →