What Is an External Attack Surface?
Your external attack surface is the collection of Internet-visible domains, hosts, services and configurations that another party can observe without internal access.
Practical, evergreen explanations built around the questions administrators, security teams and technically curious users actually ask. Read the concept first, then use Scantide to inspect the evidence.
Your external attack surface is the collection of Internet-visible domains, hosts, services and configurations that another party can observe without internal access.
SPF, DKIM and DMARC are related but different email-authentication controls. Together they help receiving systems evaluate whether a message claiming to use your domain is legitimate.
DMARC policy can begin in monitoring mode and progress toward stronger handling. Moving too quickly can disrupt legitimate senders that were never documented.
A valid certificate is only the beginning. Review expiry, hostname coverage, chain trust, redirects and whether every intended public endpoint consistently uses HTTPS.
External testing shows what a public user actually receives: whether HTTP redirects to HTTPS, whether certificates validate, and whether the HTTPS response publishes HSTS.
Public security headers reveal part of the browser hardening delivered to every visitor. HSTS, CSP, frame controls, MIME handling and referrer policy are useful evidence of configuration quality.
Old staging sites, abandoned portals and temporary hostnames can remain reachable long after the project that created them ended. External subdomain visibility helps bring them back into ownership.
DNS controls how users and systems find your web, mail and other services. Reviewing records can expose stale infrastructure, weak mail policy and unexpected providers.
A useful first-pass external review can inspect DNS, reachability, TLS, redirects, headers, cookies, service clues and infrastructure context without authenticating to the server.
Cookies visible to an external client can reveal session handling, third-party integrations and whether important attributes such as Secure and SameSite are present.
Public IP and provider information can help establish where a service appears to run and which network operates it. This is useful governance context, not a complete legal conclusion.
Public service evidence can sometimes suggest a product or version associated with known CVEs, but version matching and exposure must be handled carefully to avoid false certainty.
Certificates expire, DNS changes, providers move, subdomains appear and headers drift. Repeating external checks turns a one-time snapshot into change awareness.
The guides explain the problem. Scantide Online provides the corresponding viewpoint and evidence.
Run Scantide OnlineAll Scantide guides