Skip to content

External attack-surface auditing

What the internet knows about your domain, before somebody uses it against you

Buteo reads what your domain already publishes, from the SPF record to the certificate, from forgotten subdomains to missing headers, and hands you a list of problems with severity, history and evidence. Nothing to install, no agents, and it never touches your systems.

We only scan domains whose ownership has been proven.

The surface nobody reviews

Most organisations know what runs inside their infrastructure and far less about what their infrastructure tells the world. An SPF record ending in ~all that was never corrected, a subdomain from a 2019 campaign still pointing at a service that was cancelled, a certificate expiring on a Saturday, a security header lost in a migration. None of it shows up in an internal inventory, and all of it is visible to anyone who cares to look.

How it works

  1. 1

    Prove the domain is yours

    Publish a TXT record, place a file at a well-known location, or answer an email challenge. Until that happens the engine refuses to scan. It is not a formality: it is what separates Buteo from a scanner you can point anywhere.

  2. 2

    Buteo reads what is public

    DNS and email posture, mail transport, the DNSSEC chain, subdomains, open ports, TLS grading, headers and cookies, detected technologies, IP and ASN intelligence. It asks what the domain publishes and does not go hunting for what it hides.

  3. 3

    You get problems, not reports

    Every finding carries a severity, an explanation, context and a lifecycle of its own: new, acknowledged, resolved, accepted risk. Run it again and Buteo shows you what changed between the two, which is the question that actually matters from the second week onward.

What Buteo does not do

It does not try credentials, hunt for forgotten files, probe paths on spec, or confirm a weakness by exploiting it. A dangling CNAME is reported, never claimed. A weak cookie is reported, never replayed. This boundary is a product decision with legal consequences, and it does not move because it would be convenient on a particular engagement.

Scanning posture and abuse contact

Plans

Pricing is on request while we settle the offer. Tell us the size of your estate and we will come back with a proposal.

Free

One domain, scanned on demand.

On request

  • 1 verified domain
  • On-demand scanning
  • DNS and email posture, TLS, headers, subdomains, ports
  • PDF and DOCX report export
  • 30 days of history
  • 2 seats
Talk to us
Most chosen

Pro

For anyone who needs to know what changed since yesterday.

On request

  • Everything in Free, plus:
  • Up to 10 verified domains
  • Continuous monitoring and run-to-run comparison
  • Email alerts and a notification centre
  • Scheduled reports delivered by email
  • DNS record validator
  • Lookalike domains and cloud exposure
  • Vulnerability lookup and subdomain-takeover risk
  • One year of history
Request a proposal

Enterprise

For a group, a portfolio of brands, or auditing third parties.

On request

  • Everything in Pro, plus:
  • Unlimited domains, projects and seats
  • Daily scans
  • Service and database exposure
  • Related domains and nameserver neighbours
  • Your own branding on reports
  • API access
  • Two years of history
Talk to us
See all plans

Try Buteo on your own domain

The Free plan costs nothing: create an account, prove the domain is yours and see Buteo working on your own data rather than a screenshot.