RedScore.ai

Free outside-in domain security

What's your
RedScore on DNS?

Scan any domain in about 60 seconds. Grades, score, and what to fix first.

Attackers start with public signals. RedScore collects the same outside view and ranks what matters first. No signup.

Free scan · No signup · Results in ~60 seconds

domains
scanned
60saverage scan time

example-corp.com

Scanned just now · ~60s

42/ 100
Grade D

AI Summary

DMARC enforcement is missing, which leaves spoofing open. SPF is too permissive. Several key web security headers are absent.

FAILDMARC enforcement
FAILSPF policy strength
WARNWeb headers & TLS hardening
WARNCookie secure flag
PASSGoogle Safe Browsing

Why it matters

Your public footprint is not a secret

DNS, email auth, headers, certificates, and exposure signals are easy to check from the internet. RedScore turns that into a score and a short priority list so you are not the last to know.

Built for operators

One scan. Ten areas. Clear next steps.

Everything you need to see how your domain looks from the outside, without opening ten browser tabs.

Free outside-in scan

Enter a domain and get a public attack-surface view in about 60 seconds. No account required.

10 category grades

DNS, email, web, exposure, certificates, and more rolled into letter grades you can act on.

Fix priority, plain English

A short AI summary ranks what failed, why it matters, and what to tackle first.

Claim and monitor

Verify domain ownership to turn one-off scans into alerts and ongoing posture tracking.

What you get

One pass across your external attack surface

One scan rolls DNS, email, web, exposure, and related checks into grades you can act on, not a pile of raw tabs.

C62DNS & Domain Security
D48Email Security
B75Infrastructure Hygiene
C68Web Application Security
F32Cookie & Privacy Hygiene
D45Technology Fingerprinting
B78Public Exposure
A91Certificate & PKI Health
B82Brand & Domain Reputation
C55Third-Party Risk Surface
63/ 100
Grade C

63 / 100

Grade C

example-corp.com

AI Summary

Cookie settings are weak and server headers reveal stack details. Email spoofing is plausible with incomplete SPF and DMARC.

Email auth gaps
Header hardening
Certificate hygiene

RedScore Pro

After you claim a domain, Pro adds the operating layer

The free scan shows your public score and category grades. Claim the domain to see full findings, then upgrade to Pro when you need monitoring, reporting, and guided fixes over time.

Free accounts include scheduled scans and email alerts. Pro adds the workflows below.

Ray guidance

Site-specific fix notes on each finding after scans complete. Priority and sequencing that fit your stack.

Executive and scan PDFs

Download per-scan PDF reports and request executive summaries for stakeholders and vendor reviews.

Public trust pages

Publish a curated trust page that shows what you are doing right for customers and questionnaires.

Trend history

Track score and finding changes over time to see whether fixes are working.

Custom scan cadence

Set weekly or monthly schedules, pause a domain, and choose which modules run on each scan.

Slack, Discord, and webhooks

Route scan reports to your team channels alongside email alerts.

The difference

Enterprise posture tools vs RedScore

SecurityScorecard and Bitsight are built for enterprise procurement. RedScore gives teams the same outside-in view without a sales cycle.

Capability
Enterprise tools$25k+/yr
RedScoreFree
Outside-in domain scan
Often paid add-on
Included free
Letter grades + 0-100 score
Vendor-specific
Included free
Category breakdown
Tiered by contract
10 areas per scan
Plain-English summary
Analyst reports
Built into results
Signup to try
Sales cycle
Not required

Enterprise pricing varies by contract. RedScore basic scans stay free.

Go further with Pro

Turn a public scan into an operating workflow

01

Ray guidance

Get finding-specific fix notes and next steps after each scan completes.

02

Reports and trust pages

Create PDF reports for stakeholders and publish a curated trust page for customers.

03

Alerts and integrations

Send scan updates to Slack, Discord, webhooks, and email so fixes reach the right team.

Deeper modules

Port scanning

Find exposed services that should be closed, filtered, or reviewed.

Directory discovery

Check common public paths for admin panels, backups, and stray files.

JS secret checks

Look for tokens, keys, and sensitive config accidentally shipped to the browser.

CVE scanning

Match visible software signals against known vulnerability data.

More modules

AWS posture, code security, and more checks are on the roadmap.

FAQ

Common questions

Know your outside-in score before someone else uses it

Free scan · No signup · ~60 seconds