Skip to content
External website, DNS, email and infrastructure monitoring

Secure everything connected to the Internet

EightScope monitors your website, DNS, email and public infrastructure, scores your security posture, and maps findings to Australian Essential Eight risk indicators. Built for SMBs and MSPs who need clarity, not noise.

  • No credit card required
  • Domain verification required
  • Non-destructive external checks
OverviewDemonstration data

sample-company.example

VerifiedFull scan
View report

Security score

86/100

A

+3 since previous scan

050100

Severity summary

  • 0

    Critical

  • 0

    High

  • 4

    Medium

  • 8

    Low

  • 51

    Passed

Open findings

4 shown

Demonstration data from an anonymised sample scan.

6

attack surface areas

Website, DNS, email, TLS, subdomains and public services

Scan coverage

Up to 26 modules

Choose the right level of external assessment.

  • Quick7 modules
  • Standard15 modules
  • Full26 modules

Change tracking

See what appeared, changed or was resolved between scans.

Essential Eight

E8

External risk indicators mapped to relevant strategies.

Attack surface

What is exposed beyond your website?

EightScope examines more than the homepage. It looks at DNS, email authentication, certificates, related hostnames and other externally observable infrastructure connected to your verified domain.

See what we assess

eightscope.au

Verified domain

  • Website

    1 primary host

    HTTP behaviour, security headers, cookies and publicly exposed web paths that visitors can reach.

  • DNS

    12 records

    Records, nameservers, dangling references and other externally visible DNS configuration.

  • Email security

    SPF · DKIM · DMARC

    SPF, DKIM and DMARC configuration that is visible through public DNS records.

  • TLS certificates

    3 observed

    Certificate validity, protocol support and hostname coverage for public HTTPS services.

  • Subdomains

    6 discovered

    Related public hostnames discovered around the verified domain from external signals.

  • Public services

    4 observed

    Externally reachable services identified through safe, non-destructive checks.

How it works

From verified domain to actionable findings

Verify ownership, choose your scan coverage and receive prioritised remediation guidance.

  1. 01

    Step 01

    Add and verify your domain

    Add a DNS TXT record to confirm ownership. Verification usually takes only a few minutes.

    DNS TXT ownership check

    Domain verification

    example.com.au

    Awaiting verification

    Record type

    TXT

    Host / name

    Copy

    _eightscope-verify.example.com.au

    Verification value

    Copy

    eightscope-domain-verification=8s_demo_a1b2c3d4e5f6

    DNS updates may take time to appear. If the check fails, wait for propagation and try again.

  2. 02

    Step 02

    Choose your scan coverage

    Select Quick, Standard or Full based on the level of external coverage you need.

    External assessment depth

    Scan configuration

    Choose coverage for example.com.au

    Quick

    Fast external overview

    7 modules

    ~30 seconds

    Standard

    Broader security assessment

    15 modules

    ~2 minutes

    Full

    Complete available external coverage

    26 modules

    ~5 minutes

    Coverage7/26 modules

    Fast external preview. Checks DNS, TLS, headers, and basic web exposure on the verified apex only. No port scan or subdomain discovery.

  3. 03

    Step 03

    Prioritise what matters

    Review findings by severity, affected asset and recommended action.

    Severity, asset and guidance

    Findings

    Prioritised remediation guidance

    Selected finding

    DMARC policy not enforced

    Why it matters
    Without an enforced DMARC policy, spoofed mail can more easily impersonate your domain.
    Evidence
    Public DMARC record reports p=none.
    Recommended action
    Move DMARC from monitoring to an enforcing policy after reviewing reports.

No agent or application credentials required.

Platform

One platform. Clear external visibility.

Replace stitching together five different scanners with a single view of your website, DNS, email and public infrastructure.

Tiered scan coverage

Quick (7), standard (15), and full (26) scan depths. Full scans run all 26 external security modules, including typosquat, CVE lookup, and login-panel discovery.

Quick

7 modules

Standard

15 modules

Full

26 modules

Attack surface discovery

Subdomain enumeration, technology fingerprinting, and exposed asset inventory.

  • └ verified-domain
  • ├ www
  • ├ mail
  • └ api

Change detection

Track score changes, new findings, and regressions across scans with PostgreSQL-backed history.

Essential Eight mapping

Australian ACSC Essential Eight risk indicators, framed honestly as external risk signals, not compliance.

SSL & header analysis

Certificate health, security headers, cookie analysis, and WAF detection.

Strict-Transport-Securitypresent
Content-Security-Policyreview
X-Frame-Optionspresent

Actionable fixes

Weighted scoring with Top 5 prioritized remediation recommendations.

  • criticalOpen admin path
  • highDMARC policy
  • mediumTLS configuration

No black box

See exactly what gets checked and how results are scored.

EightScope publishes scan depths, coverage states and scoring treatment so findings stay explainable, not a mystery grade.

  1. 1Verify domain
  2. 2Discover assets
  3. 3Assess exposure
  4. 4Score findings
  5. 5Track changes

Standard scan

15 modules · ~2 minutes

Balanced coverage for ongoing monitoring: core modules plus subdomain discovery, without the slowest deep checks.

  • Subdomain discovery
  • Common ports
  • Broader coverage
  • Core + extended modules

Pricing

Start free. Upgrade when monitoring becomes essential.

AUD pricing with clear plan limits. Full feature comparison lives on the pricing page.

Free

Basic security checks for one domain.

$0/month

AUD

  • 1 domain
  • 3 quick scans + 1 standard scan per month
  • Quick and standard scans
  • Weekly monitoring (standard), included free
Start Free

Starter

A low-cost paid trial for one domain.

$10/month

AUD

  • 1 domain
  • 100 monthly scan credits
  • Quick, standard, and full scans
  • Weekly monitoring (standard default), included free
Start Starter

Pro

Recommended

Security monitoring for small businesses.

$29/month

AUD

  • 3 domains
  • 400 monthly scan credits
  • Daily monitoring (full default), included free
  • Choose days and scan frequency
Start Pro

Business

Built for agencies, MSPs, and multi-domain teams.

$99/month

AUD

  • Up to 10 domains
  • 1,000 monthly scan credits
  • Daily monitoring (full default), included free
  • Custom days and scan frequency
Start Business

FAQ

Straight answers before you start a scan.

Coverage, verification, scan depths and what EightScope is, and is not.

View all FAQs

EightScope monitors your website, DNS, email and public infrastructure. It examines internet-facing systems connected to a verified domain and helps identify exposed services, weak configurations, unexpected assets and changes over time.

It is designed to give small and medium businesses and managed service providers a clearer view of externally observable security risk.

No. EightScope performs non-destructive external security checks and attack-surface discovery.

It does not attempt to exploit vulnerabilities, bypass authentication, brute-force credentials, inject SQL, execute cross-site scripting attacks or test internal networks. A professional penetration test can provide deeper manual validation that EightScope does not replace. See the scan methodology for more detail.

Depending on the selected scan type, EightScope can assess areas including:

  • DNS and email authentication
  • TLS certificates and protocol configuration
  • HTTP security headers and cookie settings
  • open ports and publicly reachable services
  • exposed files, directories, login panels and API surfaces
  • subdomains and Certificate Transparency activity
  • public JavaScript libraries and secret-like patterns
  • cloud-storage exposure indicators
  • typosquatted domains and reputation signals
  • externally observable Essential Eight risk indicators

Exact coverage depends on the scan type, selected options, plan and whether individual checks complete successfully.

Domain verification helps confirm that you control the target or have permission to assess it. This prevents EightScope from being used as a general-purpose scanner against unrelated third-party systems.

DNS changes may take time to become publicly visible. If verification does not work immediately, check the TXT record and allow time for DNS propagation.

Quick scan (7 modules)

A fast preview of the verified root domain using the core DNS, TLS, header and basic web-exposure checks. It does not include port scanning or subdomain discovery.

Standard scan (15 modules)

The recommended regular baseline. It adds broader external checks, common-port assessment and subdomain discovery while excluding the slowest modules.

Full scan (26 modules)

The broadest available module coverage. It includes deeper checks such as typosquatting, CVE matching, login-panel discovery and additional public exposure analysis.

A Full scan still uses the normal port profile unless the deep port-scan option is selected.

No. EightScope works from the public internet and does not require an agent to be installed on your servers or devices.

EightScope does not currently perform authenticated application testing, so application usernames and passwords are not required.

Ready to monitor your external footprint?

Run your first scan in minutes. No credit card required.