Professional mapping of subdomains, technologies, and risky configurations — the same work an in-house security team would do, delivered in under 48 hours.
No agents to install, no access to your internal systems. Just what's already publicly visible — and for that same reason, the first thing an attacker would see.
Complete enumeration of active subdomains, including forgotten staging or test environments.
Identification of software, frameworks, and outdated versions that represent known risk.
PDF with findings ranked by severity and concrete recommendations for your technical team.
Start with a free snapshot. Order the full report when you want the complete picture.
Authorization notice
By requesting a snapshot or purchasing any of these plans, you confirm that you authorize the assessment of your domain and that you are the owner or an authorized representative of it. The analysis is strictly limited to passive reconnaissance of already-public information (subdomains, technologies, visible configurations). Under no circumstance is any structure, data, or system belonging to the client modified, altered, or damaged.
Start here · Free
One page for one domain: whether your SPF, DKIM and DMARC actually stop spoofing, your TLS status, how many findings we see by severity, and one of them explained. Requested from a business email address.
Additional domains $150 each.
Order report3-month minimum, or $2,490/year (2 months free).
Start monitoringRequires your written authorization and DNS access.
Order hardeningActive security researcher in public bug bounty programs.
Incorrect redirect URI configuration in their infrastructure, reported and validated.
Persistent scripting vulnerability identified and responsibly disclosed.
Active profile with a track record of verified reports in public bug bounty programs.
No. The entire analysis is performed on information that's already public, without touching your internal infrastructure.
Never. This is a purely passive reconnaissance analysis — nothing on your systems is altered, written to, or deleted.
A clear PDF, with findings prioritized by severity and actionable recommendations for your team.
Yes. Monitoring has a 3-month minimum; after that you can cancel anytime — no penalty.
Send your primary domain from your business email. Your one-page snapshot arrives within 2 business days.
or email directly at ceo@shadowperimeter.com