SCANTIDE ONLINE
Scantide Online Guide

What Is an External Attack Surface?

Your external attack surface is the collection of Internet-visible domains, hosts, services and configurations that another party can observe without internal access.

Technical guideUpdated 25 September 2026Scantide Online
Short answer: Your external attack surface is the collection of Internet-visible domains, hosts, services and configurations that another party can observe without internal access.

Start with what is publicly reachable

Websites, mail infrastructure, remote-access portals, APIs, DNS records and exposed services all contribute to the external picture.

Configuration is part of the surface

TLS versions, certificate names, security headers, redirects and DNS records can reveal weaknesses or unexpected infrastructure even when no obvious vulnerability is present.

Ownership matters as much as severity

A forgotten subdomain or server may be more important than a low-risk header finding because nobody is maintaining it.

Online provides the outside-in view

Scantide Online reviews public DNS, HTTP/HTTPS, TLS, headers, cookies, subdomains and infrastructure context to help administrators understand what outsiders can see.

Practical depth: examples, failure modes and what to verify

Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.

Current Scantide detail

Current Scantide source: External Attack Surface Assessment and Discovery

External attack surface work begins with visibility: which hosts answer, which services are exposed and which systems appear to belong to the organization.

Current Scantide source: Public Server Security Assessment

Use Scantide Online to review public hosts, HTTPS, headers, DNS and infrastructure evidence for a readable first-pass public server security assessment.

Current Scantide source: Subdomain Discovery and Public Host Assessment

Scantide Online reviews public DNS, mail-security records, HTTP/HTTPS behavior, TLS, security headers, cookies, infrastructure and CVE-related context to provide a readable external assessment of a domain.

Current Scantide source: DNS, SPF and DMARC Security Checker

Scantide Online checks public DNS and mail-security signals including SPF and DMARC as part of a broader external domain assessment.

Current Scantide source: Public Server Security Assessment

The goal is to surface systems, configuration or behavior that deserve attention and make the next administrative action easier to decide.

Field experience from the archive

Historical source · JufCorp: Securing your servers, users and customers online

Minimize the attack surface behind a good firewall that can deal with the SYN Floods and port scans and stuff. Be cautious not to open up anything more than what's absolutely necessary to and from the outside world. Use local firewalls also!

A 0day is a security bug in the software of the server your running and they vary on how much impact they may have. The name comes from that it is day 0 of it's public release and the manufacturer, in this case Microsoft, hasn't released any patch against it leaving you vulnerable no matter what you do. Some of them are even just a nifty way of adding stuff (specific strings ) to the URL or the service the attacker wants to reach and bypassing all of the built in security by "fooling" the server. Whatever they do, keep track of when they surface and see what can be done to mitigate them.

Also, you external DNS server needs to be secured! Have a word with your ISP or whoever is running the external DNS server and see what they've got in place.

Historical source · JufCorp: Securing your datacenter - Physical aspects

Know where your backups are, at all times. Have them encrypted. If using online backup services, be sure to use an encryption key and , if possible, be sure to have restrictions on the online backup service providers end on to and from where backups and restores are allowed

Historical source · JufCorp: Securing your server environment - Part III - Operating systems

Go through all services started and make sure the ones they don't use SYSTEM accounts etc unless they need to. Should the service running contain a bug and someone manages to exploit that bug, they've got SYSTEM access to your server, meaning the entire server. If you have service-users running services instead and those user are locked down, you'll minimize the damage at least When setting up the server, make sure to disable services not in use. Both from a security point of view and for performance. Windows for instance starts quite a few services that you probably don't use nor need.

Historical source · JufCorp: Security Reality Check: Why a Perfect Score Doesn't Mean You're Safe

This automated scanner focuses on infrastructure vulnerabilities, exposed services, and configuration issues. However, many critical security threats require manual testing, code review, or specialized tools. Ensure your security strategy addresses the following areas:

Practical review checklist

Frequently asked questions

Is an external attack-surface scan a penetration test?

No. It can reveal observable exposure and configuration evidence without exploiting systems.

Why scan your own public domain?

Because internal inventory may not reflect what is actually visible from the Internet.

Check the evidence with Scantide Online

External domain security, privacy and infrastructure assessment. Scantide is designed to show observable evidence and readable context rather than turn every observation into a vulnerability claim.

Run Scantide OnlineMore guidesAll Scantide guides