DNS and email authentication
DNS, DNSSEC, MX, CAA, plus SPF hardening, graded DMARC, DKIM key inspection, BIMI, MTA-STS, and DANE.
Solution
A Microsoft 365 assessment stops at the edge of the tenant. The customer’s domains, subdomains, websites, and certificates sit outside it and are where an opportunistic attacker looks first, because they need no credentials. Domain monitoring registers that footprint as assets and re-checks it on a schedule in the same workspace as the tenant.
Each registered domain and website asset is scanned on its schedule and diffed against the previous run.
DNS, DNSSEC, MX, CAA, plus SPF hardening, graded DMARC, DKIM key inspection, BIMI, MTA-STS, and DANE.
Certificate Transparency logs and DNS probing surface subdomains and forgotten hosts under the domain.
Certificate Transparency observations for new or unexpected certificates, and an expiry rollup with lead-time and urgent tiers.
HTTPS, TLS configuration, HSTS, CSP, security headers, cookies, and technology fingerprints for registered websites.
Connect-only checks for services that should not face the internet, exposed source-control or environment files, directory listing, and reachable staging.
Every issue lands in the customer’s findings queue in the same severity language as tenant findings.
External findings and Microsoft 365 findings share a severity scale and a workspace, so a technician is not switching between an attack-surface tool and a posture tool and reconciling two mental models.
A certificate approaching expiry, a new open port, or a subdomain that appeared this week generates a monitoring notification through the same alert policies as tenant changes.
When a customer asks whether they are secure, the answer covers the website and the certificates as much as the identity configuration, and the report reflects that.
MSPs inherit a customer’s external footprint at onboarding without an inventory. Passive discovery from Certificate Transparency and DNS surfaces hosts nobody listed, and a host that appears between reviews usually means an undocumented change worth a look.
Discovered hosts are shown for review and do not count against quotas or scores. You promote the ones that matter to monitored assets; the rest stay visible as context.
How subdomain, port, and certificate discovery fit together.
Tenant monitoring on the same schedule and in the same workspace.
Where domain and website findings are prioritised per customer.
CVE correlation against the technology these scans fingerprint.
External findings in the daily operations loop and the Certificates view.
Request a demo.