External Surface Scan
See what your vendor exposes online before signing the contract
Passive DNS, TLS certificates, DMARC configuration, HTTP headers, and IP reputation — all compared against what the vendor declares in the questionnaire.
Get startedVendor declares, Aranis verifies
If the vendor claims valid TLS and MFA, the scan confirms — or contradicts — in seconds.
Nothing installed on the vendor side
Fully passive scanning. No agent, no credentials, no privileged access required.
Critical change alerts
If the certificate expires, DMARC is removed, or reputation drops — you are notified.
DNS and domain registration
SPF, DKIM, DMARC, MX, NS — complete email and domain infrastructure verification.
TLS certificates
Validity, issuer, trust chain, and cipher suite configuration.
HTTP security headers
HSTS, CSP, X-Frame-Options, X-Content-Type-Options — best-practice compliance.
IP and domain reputation
Blocklists, phishing history, content categorization.
See your vendor's exposed surface
Scanning starts automatically when you create the assessment.
Get started