Free
Basic security checks for one domain.
$0/month
AUD
- 1 domain
- 3 quick scans + 1 standard scan per month
- Quick and standard scans
- Weekly monitoring (standard), included free
EightScope monitors your website, DNS, email and public infrastructure, scores your security posture, and maps findings to Australian Essential Eight risk indicators. Built for SMBs and MSPs who need clarity, not noise.
sample-company.example
VerifiedFull scanCompleted 18 minutes agoSecurity score
86/100
A+3 since previous scan
Severity summary
0
Critical
0
High
4
Medium
8
Low
51
Passed
Open findings
4 shown
| Finding | Asset | Severity | Status |
|---|---|---|---|
| Clickjacking protection missing (X-Frame-Options / frame-ancestors) | app.sample-company.example | medium | Open |
| Content Security Policy (CSP) missing | elements.sample-company.example | medium | Open |
| Cookie scoped too broadly | sample-company.example | medium | Accepted |
| MIME sniffing protection missing | elements.sample-company.example | low | Open |
Demonstration data from an anonymised sample scan.
6
attack surface areas
Website, DNS, email, TLS, subdomains and public services
Scan coverage
Up to 26 modules
Choose the right level of external assessment.
Change tracking
See what appeared, changed or was resolved between scans.
Essential Eight
E8External risk indicators mapped to relevant strategies.
Attack surface
EightScope examines more than the homepage. It looks at DNS, email authentication, certificates, related hostnames and other externally observable infrastructure connected to your verified domain.
See what we assesseightscope.au
Verified domain
Website
1 primary host
HTTP behaviour, security headers, cookies and publicly exposed web paths that visitors can reach.
DNS
12 records
Records, nameservers, dangling references and other externally visible DNS configuration.
Email security
SPF · DKIM · DMARC
SPF, DKIM and DMARC configuration that is visible through public DNS records.
TLS certificates
3 observed
Certificate validity, protocol support and hostname coverage for public HTTPS services.
Subdomains
6 discovered
Related public hostnames discovered around the verified domain from external signals.
Public services
4 observed
Externally reachable services identified through safe, non-destructive checks.
How it works
Verify ownership, choose your scan coverage and receive prioritised remediation guidance.
Step 01
Add a DNS TXT record to confirm ownership. Verification usually takes only a few minutes.
DNS TXT ownership check
Domain verification
example.com.au
Record type
TXT
Host / name
Copy_eightscope-verify.example.com.au
Verification value
Copyeightscope-domain-verification=8s_demo_a1b2c3d4e5f6
DNS updates may take time to appear. If the check fails, wait for propagation and try again.
Step 02
Select Quick, Standard or Full based on the level of external coverage you need.
External assessment depth
Scan configuration
Choose coverage for example.com.au
Quick
Fast external overview
7 modules
~30 seconds
Standard
Broader security assessment
15 modules
~2 minutes
Full
Complete available external coverage
26 modules
~5 minutes
Fast external preview. Checks DNS, TLS, headers, and basic web exposure on the verified apex only. No port scan or subdomain discovery.
Step 03
Review findings by severity, affected asset and recommended action.
Severity, asset and guidance
Findings
Prioritised remediation guidance
| Finding | Asset | Severity | Status |
|---|---|---|---|
| DMARC policy not enforced | example.com.au | high | Open |
| HTTP Strict Transport Security missing | www.example.com.au | medium | Open |
| Cookie security flags incomplete | app.example.com.au | low | Open |
Selected finding
DMARC policy not enforced
No agent or application credentials required.
Platform
Replace stitching together five different scanners with a single view of your website, DNS, email and public infrastructure.
Quick (7), standard (15), and full (26) scan depths. Full scans run all 26 external security modules, including typosquat, CVE lookup, and login-panel discovery.
Quick
7 modules
Standard
15 modules
Full
26 modules
Subdomain enumeration, technology fingerprinting, and exposed asset inventory.
Track score changes, new findings, and regressions across scans with PostgreSQL-backed history.
Australian ACSC Essential Eight risk indicators, framed honestly as external risk signals, not compliance.
Certificate health, security headers, cookie analysis, and WAF detection.
Weighted scoring with Top 5 prioritized remediation recommendations.
No black box
EightScope publishes scan depths, coverage states and scoring treatment so findings stay explainable, not a mystery grade.
15 modules · ~2 minutes
Balanced coverage for ongoing monitoring: core modules plus subdomain discovery, without the slowest deep checks.
Trust
EightScope publishes how scanning works, what is stored, and where the product’s limits are, without dressing risk indicators up as guarantees.
Pricing
AUD pricing with clear plan limits. Full feature comparison lives on the pricing page.
Basic security checks for one domain.
$0/month
AUD
A low-cost paid trial for one domain.
$10/month
AUD
Security monitoring for small businesses.
$29/month
AUD
Built for agencies, MSPs, and multi-domain teams.
$99/month
AUD
FAQ
Coverage, verification, scan depths and what EightScope is, and is not.
View all FAQsEightScope monitors your website, DNS, email and public infrastructure. It examines internet-facing systems connected to a verified domain and helps identify exposed services, weak configurations, unexpected assets and changes over time.
It is designed to give small and medium businesses and managed service providers a clearer view of externally observable security risk.
No. EightScope performs non-destructive external security checks and attack-surface discovery.
It does not attempt to exploit vulnerabilities, bypass authentication, brute-force credentials, inject SQL, execute cross-site scripting attacks or test internal networks. A professional penetration test can provide deeper manual validation that EightScope does not replace. See the scan methodology for more detail.
Depending on the selected scan type, EightScope can assess areas including:
Exact coverage depends on the scan type, selected options, plan and whether individual checks complete successfully.
Domain verification helps confirm that you control the target or have permission to assess it. This prevents EightScope from being used as a general-purpose scanner against unrelated third-party systems.
DNS changes may take time to become publicly visible. If verification does not work immediately, check the TXT record and allow time for DNS propagation.
Quick scan (7 modules)
A fast preview of the verified root domain using the core DNS, TLS, header and basic web-exposure checks. It does not include port scanning or subdomain discovery.
Standard scan (15 modules)
The recommended regular baseline. It adds broader external checks, common-port assessment and subdomain discovery while excluding the slowest modules.
Full scan (26 modules)
The broadest available module coverage. It includes deeper checks such as typosquatting, CVE matching, login-panel discovery and additional public exposure analysis.
A Full scan still uses the normal port profile unless the deep port-scan option is selected.
No. EightScope works from the public internet and does not require an agent to be installed on your servers or devices.
EightScope does not currently perform authenticated application testing, so application usernames and passwords are not required.
Run your first scan in minutes. No credit card required.