Free
One domain, scanned on demand.
On request
- 1 verified domain
- On-demand scanning
- DNS and email posture, TLS, headers, subdomains, ports
- PDF and DOCX report export
- 30 days of history
- 2 seats
External attack-surface auditing
Buteo reads what your domain already publishes, from the SPF record to the certificate, from forgotten subdomains to missing headers, and hands you a list of problems with severity, history and evidence. Nothing to install, no agents, and it never touches your systems.
We only scan domains whose ownership has been proven.
Most organisations know what runs inside their infrastructure and far less about what their infrastructure tells the world. An SPF record ending in ~all that was never corrected, a subdomain from a 2019 campaign still pointing at a service that was cancelled, a certificate expiring on a Saturday, a security header lost in a migration. None of it shows up in an internal inventory, and all of it is visible to anyone who cares to look.
Publish a TXT record, place a file at a well-known location, or answer an email challenge. Until that happens the engine refuses to scan. It is not a formality: it is what separates Buteo from a scanner you can point anywhere.
DNS and email posture, mail transport, the DNSSEC chain, subdomains, open ports, TLS grading, headers and cookies, detected technologies, IP and ASN intelligence. It asks what the domain publishes and does not go hunting for what it hides.
Every finding carries a severity, an explanation, context and a lifecycle of its own: new, acknowledged, resolved, accepted risk. Run it again and Buteo shows you what changed between the two, which is the question that actually matters from the second week onward.
Each area answers a question somebody will eventually ask, whether that is a customer, an insurer or an attacker.
Publishing an SPF record is not the same as having one that works. Buteo evaluates the rules the way a receiving server would.
What your server answers to an ordinary request says more about your posture than any written policy.
A perimeter rarely shrinks. It grows with every campaign, every vendor and every project nobody switched off.
The first scan tells you where you stand. The second, and every one after it, tells you what broke yesterday.
Audit work always ends in a document somebody non-technical has to read.
It does not try credentials, hunt for forgotten files, probe paths on spec, or confirm a weakness by exploiting it. A dangling CNAME is reported, never claimed. A weak cookie is reported, never replayed. This boundary is a product decision with legal consequences, and it does not move because it would be convenient on a particular engagement.
Scanning posture and abuse contactPricing is on request while we settle the offer. Tell us the size of your estate and we will come back with a proposal.
One domain, scanned on demand.
On request
For anyone who needs to know what changed since yesterday.
On request
For a group, a portfolio of brands, or auditing third parties.
On request
The Free plan costs nothing: create an account, prove the domain is yours and see Buteo working on your own data rather than a screenshot.