Free
Basic security checks for one domain.
$0/month
AUD
- 1 domain
- 3 quick scans + 1 standard scan per month
- Quick and standard scans
- Weekly monitoring (standard), included free
EightScope shows you that picture. Your website, your email, and everything publicly tied to your company.
sample-company.example
VerifiedFull scanCompleted 18 minutes agoSecurity score
85/100
A+3 since previous scan
Severity summary
0
Critical
0
High
4
Medium
8
Low
51
Passed
Open findings
4 shown
| Finding | Asset | Severity | Status |
|---|---|---|---|
| Clickjacking protection missing (X-Frame-Options / frame-ancestors) | app.sample-company.example | medium | Open |
| Content Security Policy (CSP) missing | elements.sample-company.example | medium | Open |
| Cookie scoped too broadly | sample-company.example | medium | Accepted |
| MIME sniffing protection missing | elements.sample-company.example | low | Open |
Demonstration data from an anonymised sample scan.
8
attack surface areas
Website, DNS, email, TLS, subdomains, public services, cloud storage and registration
Scan coverage
Up to 26 modules
Choose the right level of external assessment.
Change tracking
See what appeared, changed or was resolved between scans.
Prioritised findings
Severity and confidence decide what you see first.
Attack surface
EightScope examines eight external areas connected to a verified domain: website, DNS, email, TLS, subdomains, public services, cloud storage and registration records.
See what we assessyour domain
Verified domain
Website
1 primary host
HTTP behaviour, security headers, cookies and publicly exposed web paths that visitors can reach from the internet.
DNS
12 records
Records, nameservers, dangling references and other externally visible DNS configuration that shapes how the domain is reached.
Email security
SPF · DKIM · DMARC
SPF, DKIM and DMARC configuration published in public DNS records, which affects spoofing and delivery risk.
TLS certificates
3 observed
Certificate validity, protocol support and hostname coverage for public HTTPS services connected to the domain.
Subdomains
6 discovered
Related public hostnames discovered around the verified domain from external signals, including forgotten or unexpected hosts.
Public services
4 observed
Externally reachable services identified through safe, non-destructive checks on internet-facing infrastructure.
Cloud storage
2 linked assets
Publicly reachable cloud buckets and storage endpoints linked to the domain through hostnames or published references.
Registration
WHOIS records
Registrar, expiry and other public registration records that can signal takeover or renewal risk for the verified domain.

Scroll
Prioritisation
EightScope weighs severity and confidence to separate material external risks from findings that need validation or context. So the issues most likely to matter are easier to see first.
Ranked
The important findings rise.
Higher-severity, higher-confidence issues move up the list. Lower-confidence and informational findings stay visible without distracting from what needs attention now.
Actionable · What to work on first
EightScope turns findings into prioritised remediation guidance, showing what was found, where it was found, why it matters and the recommended next step.
How it works
Verify ownership, choose your scan coverage and receive prioritised remediation guidance.
Step 01
Add a DNS TXT record to confirm ownership. Verification usually takes only a few minutes.
DNS TXT ownership check
Domain verification
example.com.au
Record type
TXT
Host / name
Copy_eightscope-verify.example.com.au
Verification value
Copyeightscope-domain-verification=8s_demo_a1b2c3d4e5f6
DNS updates may take time to appear. If the check fails, wait for propagation and try again.
Step 02
Select Quick, Standard or Full based on the level of external coverage you need.
External assessment depth
Scan configuration
Choose coverage for example.com.au
Quick
Fast external overview
7 modules
Typical time varies by target
Standard
Broader security assessment
15 modules
Typical time varies by site size
Full
Complete available external coverage
26 modules
Duration varies with discovered assets and enabled options
Faster, lightweight assessment. Checks DNS, TLS, headers, and basic web exposure on the verified apex only. No port scan or subdomain discovery.
Step 03
Review findings by severity, affected asset and recommended action.
Severity, asset and guidance
Findings
Prioritised remediation guidance
| Finding | Asset | Severity | Status |
|---|---|---|---|
| DMARC policy not enforced | example.com.au | high | Open |
| HTTP Strict Transport Security missing | www.example.com.au | medium | Open |
| Cookie security flags incomplete | app.example.com.au | low | Open |
Selected finding
DMARC policy not enforced
No agent or application credentials required.
Platform
Replace stitching together five different scanners with a single view of your website, DNS, email and public infrastructure.
Quick (7), standard (15), and full (26) scan depths. Full scans run all 26 external security modules, including typosquat, CVE lookup, and login-panel discovery.
Quick
7 modules
Standard
15 modules
Full
26 modules
Subdomain enumeration, technology fingerprinting, and exposed asset inventory.
Track score changes, new findings, and regressions across scans with PostgreSQL-backed history.
Severity and confidence separate material external risks from noise, so you know what to fix first.
Certificate health, security headers, cookie analysis, and WAF detection.
Weighted scoring with Top 5 prioritized remediation recommendations.
Open methodology
EightScope publishes scan depths, coverage states and scoring treatment. You can see which checks ran, what they observed, and why a finding was raised.
15 modules · Typical time varies by site size
Broader security assessment for ongoing monitoring: core modules plus subdomain discovery, without the slowest deep checks.
Trust
EightScope publishes how scanning works, what is stored, and where the product’s limits are, without dressing risk indicators up as guarantees.
Pricing
AUD pricing with clear plan limits. Full feature comparison lives on the pricing page.
Basic security checks for one domain.
$0/month
AUD
A low-cost paid trial for one domain.
$10/month
AUD
Security monitoring for small businesses.
$29/month
AUD
Built for agencies, MSPs, and multi-domain teams.
$99/month
AUD
FAQ
Coverage, verification, scan depths and what EightScope is, and is not.
View all FAQsEightScope monitors your website, DNS, email and public infrastructure. It examines internet-facing systems connected to a verified domain and helps identify exposed services, weak configurations, unexpected assets and changes over time.
It is designed to give small and medium businesses and managed service providers a clearer view of externally observable security risk.
No. EightScope performs non-destructive external security checks and attack-surface discovery.
It does not attempt to exploit vulnerabilities, bypass authentication, brute-force credentials, inject SQL, execute cross-site scripting attacks or test internal networks. A professional penetration test can provide deeper manual validation that EightScope does not replace. See the scan methodology for more detail.
Depending on the selected scan type, EightScope can assess areas including:
Exact coverage depends on the scan type, selected options, plan and whether individual checks complete successfully.
Domain verification helps confirm that you control the target or have permission to assess it. This prevents EightScope from being used as a general-purpose scanner against unrelated third-party systems.
DNS changes may take time to become publicly visible. If verification does not work immediately, check the TXT record and allow time for DNS propagation.
Quick scan (7 modules)
A fast preview of the verified root domain using the core DNS, TLS, header and basic web-exposure checks. It does not include port scanning or subdomain discovery.
Standard scan (15 modules)
The recommended regular baseline. It adds broader external checks, common-port assessment and subdomain discovery while excluding the slowest modules.
Full scan (26 modules)
The broadest available module coverage. It includes deeper checks such as typosquatting, CVE matching, login-panel discovery and additional public exposure analysis.
A Full scan still uses the normal port profile unless the deep port-scan option is selected.
No. EightScope works from the public internet and does not require an agent to be installed on your servers or devices.
EightScope does not currently perform authenticated application testing, so application usernames and passwords are not required.
Run your first scan in minutes. No credit card required.