Domain Risk HeatMap
Get a clear picture of risks, impact and recommended actions.
A visual audit of the domain’s public infrastructure, showing how the website, DNS, email, CDN, WAF, server, CMS and related technologies are connected — and where risk indicators are detected.
Domain Dependency & Risk Map analyses the public technical footprint of a domain and organises the findings into an interactive infrastructure map.
This allows business and technical teams to quickly answer questions such as:
- Is the domain properly configured and active?
- Are DNS and email services correctly exposed?
- Is there evidence of CDN or WAF protection?
- Where are the strongest risk signals located?
- Are there missing, weak or unclear layers in the domain setup?
9 analyses included
TLS Connection & Certificate
Checks that the site serves HTTPS with a valid, in-date certificate, detects support for outdated TLS versions and verifies the redirect from HTTP to HTTPS
Security Headers
Analyzes a website's HTTP security headers, verifies their presence and validates that the values are secure and correctly configured, and passively detects whether a WAF or anti-bot protection is in place
Information Exposure
Detects sensitive information leaks such as software versions in headers, accessible configuration files, backups and directory listings
Essential Performance
Measures key speed indicators of the main page: server response time (TTFB), page weight, compression, HTTP protocol version and cache headers
Asset Optimization
Checks CDN usage for static assets, modern image formats and preconnect/dns-prefetch configuration for external web font providers
Essential SEO & Metadata
Checks essential HTML metadata for SEO and social sharing (title, meta description, favicon, canonical, meta robots, H1, lang, viewport, Open Graph, structured data) and validates the existence and correctness of robots.txt and sitemap.xml
Essential Accessibility
Checks essential web accessibility criteria (WCAG) on the public HTML: alternative text on images, semantic landmarks, links/buttons without accessible text, and declared language
DNS & Email Reputation
Checks the domain's SPF, DKIM and DMARC records to detect the risk of email spoofing, verifies whether its IP appears on spam blacklists (DNSBL) and confirms whether the domain has DNSSEC correctly configured (not just whether it publishes a DS)
Compliance & Trust
Checks for the presence of legal links (privacy, cookies, legal notice), a cookie consent banner, tracking scripts and mixed content
What this audit does not cover
All checks are performed remotely against publicly reachable endpoints, without authentication and without any destructive or exploitative action.
This audit does not include:
- Active exploitation or penetration testing against the target
- Authenticated or credentialed testing, including logins, admin panels, private areas, or internal systems
- Source code review or static application security testing
Load testing, denial-of-service simulation, stress testing, or destructive checks - Manual legal review or formal compliance certification
Full SEO audit, content audit, or backlink analysis - Malware removal, incident response, or forensic investigation
- Infrastructure review beyond externally observable indicators
- Guaranteed detection of all vulnerabilities, misconfigurations, outages, or compliance issues