External Surface Scan

See what your vendor exposes online before signing the contract

Passive DNS, TLS certificates, DMARC configuration, HTTP headers, and IP reputation — all compared against what the vendor declares in the questionnaire.

Get started

Vendor declares, Aranis verifies

If the vendor claims valid TLS and MFA, the scan confirms — or contradicts — in seconds.

Nothing installed on the vendor side

Fully passive scanning. No agent, no credentials, no privileged access required.

Critical change alerts

If the certificate expires, DMARC is removed, or reputation drops — you are notified.

DNS and domain registration

SPF, DKIM, DMARC, MX, NS — complete email and domain infrastructure verification.

TLS certificates

Validity, issuer, trust chain, and cipher suite configuration.

HTTP security headers

HSTS, CSP, X-Frame-Options, X-Content-Type-Options — best-practice compliance.

IP and domain reputation

Blocklists, phishing history, content categorization.

See your vendor's exposed surface

Scanning starts automatically when you create the assessment.

Get started