How EightScope monitors your website, DNS, email and infrastructure
EightScope examines the internet-facing systems connected to a domain you control. It works from the public internet, without internal network access or customer credentials, to identify exposed services, weak configurations, unexpected assets and changes over time.
EightScope is designed to provide a clear view of externally observable risk. It combines attack-surface discovery, security checks, prioritised findings and repeatable monitoring in one place.
Authorisation and safety
Domain ownership
Before a production scan can run, the domain must be added to the customer’s organisation and ownership must be verified using a DNS TXT record.
Scanning is restricted to:
the verified root domain
subdomains belonging to that verified domain
public internet-facing services associated with those hostnames
EightScope does not allow customers to use the platform as a general-purpose scanner for unrelated third-party targets.
Safe target validation
Before contacting a hostname, EightScope resolves its DNS records and checks the returned addresses.
Scanning is blocked when a hostname resolves to:
private network addresses
loopback addresses
link-local addresses
reserved or otherwise non-public addresses
a mixture of public and non-public addresses
This helps prevent the scanner from being used to reach internal services, cloud metadata endpoints or other unsafe destinations.
If a redirect leaves the verified domain’s scope, EightScope does not continue assessing the external destination as though it belonged to the customer.
Non-destructive scanning
EightScope focuses on externally observable configuration and exposure. It does not attempt to damage systems, bypass authentication, brute-force passwords or exploit discovered vulnerabilities.
Some deeper checks, particularly full TCP port scanning, can still trigger firewall, hosting or security-monitoring alerts. Customers should run these checks only against systems they are authorised to assess.
How a scan works
1
Verify the domain
The customer adds a domain and proves control using a DNS TXT record. This establishes the permitted scan boundary.
2
Discover internet-facing assets
Depending on the selected scan type, EightScope uses public certificate data, DNS-based discovery and other external signals to identify hostnames connected to the verified domain. Discovery is not the same as a completed security assessment. A hostname can be discovered without being selected for every scan module.
3
Build the asset inventory
Each in-scope hostname receives its own asset record. EightScope records information such as hostname, resolved public IP addresses, discovery source, HTTP and HTTPS reachability, CDN indicators, TLS assessment status, HTTP-header assessment status, and reasons a check was skipped or blocked.
4
Select assets for applicable checks
Some checks can run against every relevant result, while other checks are limited to a selected set of hosts so scans remain safe, timely and predictable. Selection is deterministic and prioritises useful targets such as reachable web services, the www hostname and security-sensitive names such as admin, login, vpn, api, staging, mail and similar services.
5
Run the selected security modules
The selected scan type determines which modules run. Checks collect external evidence and produce structured findings with affected asset, check name, status, severity, confidence, evidence, explanation and recommended remediation.
6
Score and compare the results
EightScope calculates the posture score from open findings and compares completed scans only when the coverage is suitable for comparison. A deeper scan may produce a lower score simply because it assessed more of the attack surface. That does not always mean the organisation became less secure.
Scan types
Module counts stay aligned with the product so this page reflects what customers can run today.
Quick scan
7 modules · ~30 seconds
A fast external preview of the verified root domain. Quick scans cover core DNS, TLS, HTTP-header and web-exposure checks.
assesses the verified root domain only for TLS and HTTP headers
does not perform port scanning
does not perform subdomain discovery
does not represent full attack-surface coverage
useful for an initial preview or a fast recheck
Standard scan
15 modules · ~2 minutes
The recommended baseline for regular posture monitoring. Standard scans combine core security checks with subdomain discovery, common-port assessment and broader external coverage while excluding the slowest modules.
discovers related hostnames
assesses common externally reachable services
checks TLS and HTTP headers across selected assets
excludes heavier checks such as typosquatting, CVE matching and open-redirect probing
best suited to recurring monitoring
Full scan
26 modules · ~5 minutes
The broadest EightScope assessment. Full scans run every available external security module, including deeper discovery and higher-cost checks.
includes all standard coverage
includes typosquatting checks
includes CVE matching against detected technologies
includes login-panel and API-surface discovery
includes public JavaScript secret-pattern checks
includes service-banner and reputation checks
still uses the normal common-port profile unless the deep port-scan option is selected
A deep port scan checks all 65,535 TCP ports and requires the relevant option and customer consent. When a normal port scan runs, EightScope also performs limited UDP checks for ports 53, 123 and 161. UDP coverage is not exhaustive.
What we assess
DNS and email security
EightScope may assess
DNS resolution and record configuration
mail exchange records
SPF
DMARC
common DKIM selectors
DNSSEC indicators
CAA records
email-related configuration weaknesses
DKIM discovery checks common selectors. An organisation may use a valid custom selector that EightScope does not discover.
TLS and certificate security
EightScope may assess
certificate validity and expiry
hostname matching
certificate chain information
self-signed certificates
supported protocol versions
selected cipher and transport indicators
alternate HTTPS services when deep TLS assessment is enabled
OCSP-related indicators when supported by the selected scan options
HTTP and browser protections
EightScope may assess
HTTPS availability
HTTP Strict Transport Security
Content Security Policy
framing protections
referrer policy
permissions policy
cookie Secure, HttpOnly and SameSite attributes
redirect behaviour
web application firewall indicators
publicly visible HTTP behaviour
Ports and exposed services
EightScope may assess
common TCP ports
all TCP ports when deep port scanning is enabled
limited UDP services
public service banners
exposed administration services
remote-access services
mail and infrastructure services
software-version information exposed by services
An open port is not automatically a vulnerability. Its severity depends on the service, exposure, configuration and available evidence.
Secret detection is pattern-based. A matching value may be a real credential, a test value or a false positive and should be validated before action is taken.
Attack-surface and brand signals
EightScope may assess
discovered subdomains
Certificate Transparency activity
possible subdomain-takeover conditions
lookalike or typosquatted domains
unusual public assets
domain-reputation signals
Safe Browsing signals when the required provider integration is configured
When a provider integration is unavailable, the result must be shown as not assessed rather than passed.
This mapping is provided to help customers organise risk. Many Essential Eight controls cannot be reliably assessed from the public internet, including internal application control, patch-management processes, administrative privileges, MFA coverage, backup practices and internal Microsoft Office settings.
The mapping is not an Essential Eight maturity assessment or compliance certification.
Asset coverage
Discovery does not equal assessment.
EightScope lists the hostnames it discovers, but not every discovered hostname receives every security check during a single scan.
DNS coverage
DNS resolution is attempted for discovered in-scope hostnames. Hostnames that do not resolve, return unsafe addresses or produce lookup errors are kept in the inventory with an appropriate status.
HTTP and HTTPS reachability
Reachability probing is capped and prioritised. A hostname that was not probed must be shown as not probed, not as unreachable or secure.
TLS and HTTP-header coverage
For Standard and Full scans, EightScope assesses:
the verified root domain
up to 20 selected non-root hostnames
For Quick scans, TLS and HTTP headers are assessed on the verified root domain only.
For non-root hostnames, reachable HTTP or HTTPS services are prioritised. Within those groups, www and security-sensitive hostnames receive higher priority, followed by deterministic hostname ordering.
Hostname-aware assessment
TLS and HTTP headers are assessed separately for each hostname using the hostname’s own TLS SNI and HTTP Host identity.
Two hostnames are not treated as equivalent merely because they use:
the same IP address
the same hosting provider
the same reverse proxy
the same CDN
This matters because different hostnames on shared infrastructure can present different certificates, redirects, headers, applications and security configurations.
Coverage states
Assessed
The module completed meaningful checks against the asset.
Not assessed
The asset was discovered but the module did not run or was outside the applicable scan limit.
Not probed
The asset was discovered but was not selected for an HTTP or HTTPS reachability probe.
Blocked for safety
The hostname resolved to a non-public or otherwise unsafe destination.
Assessment error
The check began but could not complete because of a timeout, connection problem or scanner error.
Inconclusive
The scan collected some evidence but could not make a reliable pass or fail decision.
None of these incomplete states should be interpreted as confirmation that an asset is secure.
Findings, severity and confidence
Finding status
Finding status meanings
Status
Meaning
Pass
The tested condition met the check’s requirements at the time of the scan.
Fail
Evidence indicates a security issue or unsafe condition.
Warning
Evidence indicates a weakness, concern or condition requiring review.
Inconclusive
There was not enough reliable evidence to make a pass or fail decision.
Skipped / not assessed
The check did not run or could not safely complete.
Only open Fail and Warning findings can reduce the headline posture score. Passed, skipped and inconclusive findings do not reduce it.
Severity
Severity meanings
Severity
General meaning
Critical
Direct or severe exposure that may enable serious compromise and requires immediate review.
High
Material security weakness with significant potential impact.
Medium
Meaningful weakness with lower immediate impact or exploitability.
Low
Security-hardening or hygiene issue with limited direct impact.
Informational
Context that may help investigation but does not directly reduce the score.
Severity represents EightScope’s assessment of the observed external condition. It is not a complete business-risk calculation because EightScope does not know every asset’s business value, data sensitivity or internal compensating controls.
Confidence
Confidence levels and score treatment
Confidence
Meaning
Score treatment
Confirmed
Direct evidence supports the finding.
Full severity deduction.
Likely
Evidence strongly suggests the finding, but manual validation may still be needed.
Half severity deduction, rounded down.
Possible
A weak or indirect signal requires validation.
No score deduction.
Possible findings remain visible so customers can investigate them without allowing uncertain detections to unfairly damage the headline score.
How the posture score works
Headline score
The EightScope posture score starts at 100 and subtracts points for open findings.
Score deductions by severity and confidence
Severity
Confirmed deduction
Likely deduction
Possible deduction
Critical
12
6
0
High
6
3
0
Medium
3
1
0
Low
1
0
0
Informational
0
0
0
Likely deductions are calculated at half weight and rounded down to a whole point. The final score is limited to a range from 0 to 100.
Repeated findings and score caps
EightScope avoids allowing one repeated configuration problem to overwhelm the headline score.
For host-level configuration checks, such as the same missing security header appearing across many hostnames, only the worst scoring instance from that check family contributes to the headline score.
Every affected hostname remains visible in the findings and asset inventory.
Distinct exposures can still contribute separately when they represent separate security targets, including:
different open ports
different exposed files
different URL paths
different API endpoints
Duplicate cookie-security findings covering the same cookie are collapsed to the worst relevant instance for scoring.
Module scores
Individual module scores are intended for drill-down and may use module-specific behaviour. They may not exactly match the calculation used for the overall headline score.
Letter grades
Letter grades from numeric score
Score
Base grade
90 to 100
A+
80 to 89
A
70 to 79
B
60 to 69
C
40 to 59
D
Below 40
F
Grade safety rules (ceilings only; never upgrades):
A confirmed Critical finding prevents the grade from being higher than C. It cannot improve a lower grade.
Scores below 40 remain F, even when a confirmed Critical finding exists.
Three or more High findings that are not classified as Possible also prevent the grade from being higher than C.
These ceilings prevent a high numeric score from hiding severe findings. They never raise a poor grade.
Optional AI-assisted wording
Optional AI-assisted report wording never changes findings, evidence, severity, priority, score or grade. EightScope remains authoritative for those results.
When enabled, AI may only write an executive summary, rewrite or summarise existing EightScope explanations and remediation guidance for up to eight findings in EightScope's existing priority order, and paraphrase scan limitations. It is not used as an authoritative source for new findings, CVEs, evidence, severity, priority or remediation.
Inputs are allowlisted and sanitised. EightScope does not send the complete scan result, raw evidence, hostnames, email addresses, IP addresses or WHOIS records to the model by design.
Generated output is validated. Output that introduces unsupported claims or structural changes is rejected and is not stored or displayed.
When AI-assisted wording is enabled and a generation runs, processing uses Amazon Bedrock in the Sydney region (ap-southeast-2).
AI-assisted wording is optional and off by default. Opening a saved report or downloading a PDF reads stored ready output only and does not call the model again.
EightScope monitoring runs scheduled batch rescans using the frequency and scan depth available on the customer’s plan and domain settings.
Scheduled monitoring is not real-time or continuous surveillance. Changes that occur between scheduled scans may not be detected until the next scan runs.
Scheduled monitoring scans do not consume the customer’s manual monthly scan credits.
Comparable scans
EightScope avoids claiming that a finding was fixed when the later scan did not reassess it.
successful reassessment of the relevant asset and module
For example, a Quick scan must not mark a Full-scan finding as resolved when the Quick scan did not run that module.
Finding identity
Findings are tracked using stable information including:
affected asset
scan module
check identifier
relevant port, path, file or endpoint
This allows the platform to distinguish between new findings, ongoing findings, resolved findings, severity changes and asset-specific changes.
Methodology changes
When EightScope changes its asset-coverage or finding-identity methodology in a way that would make historical comparisons misleading, the methodology version is changed.
Scans using incompatible methodology or coverage should not be presented as directly comparable without a clear warning.
Interpreting score changes
A lower score does not always mean security became worse. It may also occur because:
a deeper scan type was used
more assets were discovered
more modules completed successfully
a previously unreachable asset became assessable
the scoring methodology changed
The scan comparison should explain these coverage differences wherever possible.
Known limitations
EightScope does not perform
authenticated application testing
SQL injection or cross-site scripting exploitation
form fuzzing
payment-flow testing
credential attacks
internal network scanning
endpoint or device assessment
identity-provider or MFA configuration review
source-code analysis
cloud-account CSPM for AWS, Azure or Google Cloud
full Essential Eight maturity assessment
exhaustive UDP scanning
guaranteed discovery of every subdomain, asset or DKIM selector
Other limitations
firewalls, WAFs, CDNs and rate limits can affect results
public certificate and DNS data may be incomplete or delayed
technologies can hide or falsify version information
network timeouts can prevent checks from completing
a public service can change immediately after a scan
CVE matching depends on reliable technology and version detection
secret-pattern and exposure checks can produce false positives
some vulnerabilities cannot be identified without authentication or exploitation
Safe Browsing and other third-party checks depend on provider availability and configuration
EightScope is one layer of a security program. Important findings should be validated, prioritised using business context and combined with internal security testing where appropriate.
How to use your results
1Review Critical and High findings first.
2Confirm whether the affected asset is still required and intended to be public.
3Validate Likely and Possible findings before making disruptive changes.
4Review every asset marked Not assessed, Not probed, Blocked or Error.
5Follow the finding’s remediation guidance and keep evidence of the change.
6Rerun the same scan type to confirm remediation.
7Investigate newly discovered hostnames and unexpected score changes.
8Use Full scans periodically for broader coverage, not only after an incident.
9Combine EightScope with internal vulnerability management, patching, access control, backups and incident response.