Secri Radar's AI engine continuously maps your entire domain attack surface — predicting subdomain takeovers, detecting DMARC spoofing, and alerting your team before threats escalate into breaches.
Subdomain takeover risk
staging.acme.com
CNAME → deprovisioned Heroku app
Dangling CNAME detected
cdn.acme.com
Points to deleted CloudFront distribution
Orphan subdomain
old-api.acme.com
No DNS response — potentially abandoned
100+
AI-trained risk signatures
< 5 min
Threat alert latency
24 / 7
AI engine uptime
4 methods
Discovery techniques
RFC 7489
DMARC standard
2 products
Domain + Email security
How it works
01
Enter the root domain you want to protect. No DNS changes required — we work entirely from the outside in, just like an attacker would.
02
AI-powered scanners run 24/7 — parsing CT logs in real time, running intelligent DNS permutations, and fingerprinting every discovered subdomain against 100+ vulnerability signatures.
03
When our AI confirms a verified takeover risk or suspicious asset, you're alerted within minutes via email, Slack, or webhook — with full context to act immediately.
Features
Domain Monitor protects your attack surface. DMARC Analyser secures your email identity. Use them together or independently.
Domain Monitor
Subdomain discovery & takeover detection
Our AI engine monitors Certificate Transparency logs, runs intelligent DNS permutations, and taps 30+ passive sources to find subdomains the moment they appear.
Machine-learning-assisted wordlists and permutation engines predict likely subdomain patterns — surfacing shadow IT and forgotten assets before attackers do.
Our AI risk engine probes discovered subdomains and matches HTTP responses against 100+ cloud-service signatures, automatically scoring each finding by exploitability.
Dangling CNAMEs, orphaned S3 buckets, deprovisioned Heroku apps — our AI correlates DNS chains and service signals to flag exploitable misconfigurations in real time.
AI-driven two-scan confirmation eliminates false positives. Only verified, persistent threats trigger alerts — so your team acts on signal, not noise.
Every discovered subdomain is cross-referenced against Google's Safe Browsing threat intelligence — instantly flagging compromised or malware-serving assets.
DMARC Analyser
Email authentication monitoring & reporting
Receive DMARC RUA reports automatically via a dedicated email address. No DNS changes needed beyond adding the rua= tag to your existing record.
Instantly see which sending IPs are passing DKIM and SPF checks and which are failing — broken down by day, reporter, and source IP.
See where your email is originating from. Every source IP is resolved to a country and plotted in an interactive donut chart.
Identify your highest-volume sending IPs, their authentication status, and when they were last seen — in a single ranked table.
Print or save a one-page PDF summary of your DMARC health — designed for stakeholder reporting without exposing raw log data.
Get notified when new senders fail DMARC authentication so you can respond before spoofed email reaches your customers.
The threat landscape
Industry data shows how widespread — and costly — unmonitored domains have become.
1 in 5
DNS records vulnerable to subdomain hijacking
CSC Research, 440k+ records
$55B
lost to Business Email Compromise over the past decade
FBI IC3
13,000
brand subdomains hijacked in a single 2024 phishing campaign
Guardio Labs — SubdoMailing
82%
of domains have no DMARC enforcement — freely spoofable
PowerDMARC global survey
How attackers exploit it
When a CNAME points to a cloud service you no longer own — an S3 bucket, a Heroku app, a Fastly endpoint — an attacker registers that service and serves arbitrary content from your domain, with full HTTPS and a valid certificate.
Threats we detect
Every vector. Automatically.
Dangling CNAME records
Unregistered cloud endpoints an attacker can claim
Abandoned S3 / GCS buckets
Deleted storage still referenced by live DNS
Deprovisioned Heroku / Netlify apps
Expired PaaS apps with claimable namespaces
Expired Fastly / CloudFront origins
CDN misconfigurations pointing to thin air
DMARC spoofing vectors
Domains with no enforcement — freely impersonatable
Pricing
Choose Domain Monitor, DMARC Analyser, or bundle both and save.
Bundle Basic
or $650/year — save ~10%
Domain Monitor + DMARC Analyser at a discount.
Bundle Pro
or $2,149/year — save ~10%
Full coverage across both products.
Enterprise
Custom pricing for large organisations.
All plans include a 14-day free trial. No credit card required to start. See full feature comparison →
Add your first domain in under a minute. No credit card required.
Create your free account