Method · what actually happens

You give us a domain. A person reads the public record and writes to you.

There is no dashboard, no login and no automated pipeline behind this. At launch a human being does the reading, the judging and the writing, and that is the reason the report is worth your time. Here is every step of it — including the parts we are deliberately not allowed to do.

Cost
Free · one domain · once every 30 days
Turnaround
One to two business days
Delivered by
A person, by email
Contact with you
One public DNS lookup

01 The process

Four steps. Three of them are ours.

  1. Step 1 About a minute

    You enter your domain and a work email

    That is the entire form. Nothing to install, no payment details, no account to create. You also tick two confirmations that carry real weight — that you are authorised to request an assessment of that domain, and that you understand this is not a penetration test — and each is stored with the exact wording you were shown and the time you agreed to it.

  2. Step 2 Minutes

    We read what is already public

    We look up your public DNS records and the mail posture they describe, query public certificate transparency logs held by a third party, and read the public domain registry entry. We never connect to your website or servers, never log in, and never test your defences.

  3. Step 3 One to two business days

    A person reads it, judges it and writes it up

    Every report is read by a human being before it is sent. This is the expensive part and it is the point. Automated tools are famous for producing pages of alarming findings that turn out to be irrelevant, and a business owner has no way to tell which is which. Ours does not go out until somebody has checked that each finding is real, that it matters for a business like yours, and that the explanation makes sense to a reader who is not technical. Weekends and public holidays push it to the longer end; if it will take longer than that, we email and say so.

  4. Step 4 Yours to keep

    You get the report and decide what to do

    It arrives by email. Not everything we found — the three things that matter most, in order, each with a preferred fix, a cheaper fallback, and who should own it: you, your IT provider, your hosting company, or us. Where a fix is something you can do yourself in an afternoon, the report says so instead of selling you anything.

02 What we read

Four public records, and a check that never leaves your browser

Public records · acaciagardens.example $ dig +short · crt.sh · rdap
NS
ns1.host.example · ns2.host.example
MX
mail.acaciagardens.example (priority 10)
TXT · SPF
v=spf1 include:_spf.mailhost.example ~all
TXT · _dmarc
no record published
CT log
booking-staging.acaciagardens.example · issued 2026-03-11
CT log
www.acaciagardens.example · issued 2026-06-02
RDAP
registrar lock: not set · expires 2026-11-04

An illustration on a reserved domain that cannot exist. Every line is the kind of record a snapshot reads, and every one is published by somebody other than you: your DNS operator, a certificate log, a domain registry.

SPF ends in ~all. A soft fail asks receiving mail servers to accept a forged message and merely mark it. What to set instead: the SPF, DKIM and DMARC guide.

No DMARC. With no policy published, a receiving server has been given no instruction about what to do with a message that fails those checks — so a forgery sent to a customer or a supplier can arrive looking ordinary.

A staging hostname in the certificate log. Published permanently, by design, the moment a certificate was issued for it. We do not connect to it. We tell you your own certificates announced it.

Registrar lock not set. A domain that moves without your knowing takes your website and your email with it.

  • Your public DNS records

    Where your website resolves, who runs your name servers, what mail servers you publish, and what stray records are still there from a supplier you stopped using. Forgotten records are how a business ends up with a subdomain nobody owns any more, still pointing somewhere.

  • Your mail posture, derived from those records: SPF, DKIM, DMARC

    These are the settings that tell the world's mail servers whether a message claiming to come from your domain is genuine. When they are missing or misconfigured, somebody can email your guests, your patients or your suppliers from what looks like your address and ask them to pay a different account. The fix is a change to public DNS records: nothing to buy, nothing to install.

  • Certificate transparency logs

    Every HTTPS certificate issued for your domain is written to a public log, permanently, by design. We read those logs — held by third parties, not by you. They often list internal-sounding names a business never meant to publish: a staging server, an old booking system, an admin panel.

  • The public domain registry entry

    Your registrar, when the registration expires, and whether it is locked against transfer. That is a public record held by the registry, not something we ask your systems for.

  • Optionally, a password check that runs inside your browser

    You can check whether a password you use has appeared in a known public breach. The check runs entirely on your device. The password never leaves it, and neither does the full fingerprint of it — only the first five characters of that fingerprint are sent, and they go to Have I Been Pwned (api.pwnedpasswords.com), a public breach index run by a third party, not by us. Because your browser makes that request itself, they can see your IP address, exactly as any website you visit can. They never receive your password, your full fingerprint, your domain or your email. Neither do we: there is no page on this site that asks you to type a password and send it to us.

03 What we never touch

It also means there are real things a free snapshot cannot see: your internal network, your staff laptops, your point-of-sale, your Wi-Fi. A clean external picture is good news about the outside and nothing more, and the report says so on its front page.

We read public records. We do not connect to you.

The claim, in full

We read public records — DNS, mail records, certificate transparency logs and the domain registry. We never connect to your website or servers, never log in, and never test your defences.

And one honest qualification, because the absolute version of that sentence would be false. Looking up a domain asks whichever name servers are authoritative for it, and those may be machines you or your provider run. So we will not tell you that nothing of ours ever reaches anything of yours — anyone who tells you their outside-in check does that is describing something which cannot be done. What we will say precisely is this: the only contact is a public DNS lookup of the same kind every mail server on the internet makes to find you, and nothing we do opens a connection to your website, your ports or your applications.

For a domain you have not verified, we perform no TLS handshakes with your servers, no HTTP requests to your website, and no port probing. That is not a policy anybody could quietly relax on a busy afternoon: it is enforced in our software, and a free snapshot is recorded in a form that cannot represent anything else.

The reason is the law rather than modesty. Kenya's Computer Misuse and Cybercrimes Act 2018, as amended in 2025, draws a clear line between reading what is published and connecting to somebody's system to test it. The second requires their written authority, Kenya has no responsible-disclosure safe harbour, and probing systems classed as protected — hospitals and payment systems among them — carries penalties up to KES 25 million and 20 years. We would rather be visibly on the right side of that line than slightly more impressive.

04 The report

Read the sample before you give us anything. It is the answer to the only sensible question about a company with no track record: is the work any good?

What arrives, and what it will not pretend

  • An A to E rating, with its reasons

    Not just a letter: the findings that produced it, and how they were weighed.

  • An honest confidence level

    A free snapshot rests on external evidence only, so it is never rated high confidence. The report states that on the front page, along with how much of the full picture the rating rests on.

  • Your top three issues, ranked, in plain language

    Each with what it would actually cost your business, a preferred fix, a cheaper fallback, and who should own it.

  • What is already working

    Most businesses have something right and are never told which parts.

  • A 30-day plan

    What to fix first, roughly how hard each item is, and in what order.

Read a full sample report

05 Afterwards

One free snapshot per domain every 30 days. The limit exists because a person does the work, not because of a plan tier.

Then nothing happens, unless you ask

The free snapshot is one day's picture. We do not keep watching your domain, nothing will alert you if something changes, and no sales sequence starts. If the report is useful and you want nothing else from us, that is a fine outcome.

If you do want the same records read again each month, that is Watch — a person re-reading them and writing you a short note, not a watching service. If you want the work done rather than described, that is a fix sprint. Both are on the pricing page, with the prices on them.

06 After verification

Verification is also what Watch and the Website Cleanup sprint require, for the same reason: we will not do repeated or connecting work on a domain we cannot show you asked us to.

Two useful checks are missing on purpose

What your live website actually serves, and how your TLS is configured, are both genuinely worth knowing — and both require connecting to your systems. Kenyan law says we need your permission first, so they stay switched off until you prove you control the domain or give us written authorisation.

Proving domain control takes about ten minutes: a DNS record we give you, a file on your web server, or a code sent to an address at your own domain. Once it is done, those checks unlock and they are still free.

One free snapshot per domain every 30 days. We read public records — DNS, mail records, certificate transparency logs and the domain registry. We never connect to your website or servers, never log in, and never test your defences. This is not a penetration test.

Find out what a stranger already knows about your business

One domain, read from public records, written up by a person and emailed to you in one to two business days. Free. Nothing to install, no payment details, no account.

Get my free snapshot Read a sample report first