Buteo

Buteo

External attack-surface auditing

What the internet knows about your domain, before somebody uses it against you: scored findings with evidence, and every scan compared with the last.

Get in Touch See All Products
What changed since the last scan
Last scan DMARC rejecting, 14 subdomains, certificate valid 40 days
This scan DMARC observing, 15 subdomains, certificate valid 12 days
Δ
The diff

What appeared, what went away, what changed severity. Recorded as events with a history.

Alert A policy that stopped rejecting, a subdomain nobody asked for
Noise Recurring churn, kept in the history and out of the inbox
Where it runs As a service. Nothing installed, and only domains you have proven you own

The outside view

Buteo reads what your domain already publishes to the internet, from the SPF record to the certificate, from forgotten subdomains to missing headers, and turns it into scored findings with evidence and a lifecycle. Then it scans again and tells you what changed. Nothing to install, no agents, and it never touches your systems: it only scans domains whose ownership has been proven, and it reports a weakness rather than exploiting it.

Ibex is the inside view, the sealed appliance on the network the cloud cannot reach. Buteo is the other one: your domain as anyone on the internet sees it. A buteo is a buzzard, the hawk that circles high and reads the ground below, which is exactly the vantage point it takes.

The surface nobody reviews

Most organisations know what runs inside their infrastructure, and far less about what their infrastructure tells the world. An SPF record ending in a soft fail that was never corrected. A subdomain from a 2019 campaign still pointing at a service that was cancelled. A certificate expiring on a Saturday. A security header lost in a migration.

None of it shows up in an internal inventory, and all of it is visible to anyone who cares to look. When it is found, it is usually found by the wrong person first.

Problems, not reports

Buteo asks what the domain publishes and evaluates it the way a receiving server or a browser would: not whether an SPF record exists, but whether it stops a forged message; not whether DMARC is set, but whether it is rejecting or merely observing.

Every finding carries a severity, an explanation, its evidence and a lifecycle of its own. Run it again and Buteo shows what changed between the two, which is the question that actually matters from the second week onward.

Proven first, passive always

Two rules separate Buteo from a scanner you can point anywhere.

The engine refuses to scan a domain until its ownership is proven: a TXT record, a file at a well-known location, or an email challenge. And it never tries credentials, hunts for forgotten files, probes paths on spec or confirms a weakness by exploiting it. A dangling CNAME is reported, never claimed. A weak cookie is reported, never replayed. The boundary is a product decision with legal consequences, and it does not move because it would be convenient on a particular engagement.

Key features

Ownership proven first

A TXT record, a well-known file or an email challenge. Until one succeeds, the engine refuses to scan.

Email posture that works

SPF resolved in full with its lookup count, DMARC checked for whether it rejects, the DNSSEC chain followed to the root.

TLS, headers and cookies

Protocols and ciphers graded, the certificate chain and its time left, each missing header with what its absence permits.

The perimeter you forgot

Subdomains, dangling CNAMEs open to takeover, reachable ports, IP ranges and ASNs, and lookalike domains registered by others.

What changed since yesterday

Every scan is compared with the last. Alertable change is separated from recurring noise, and the events feed a history.

Findings with a lifecycle

Severity, explanation and evidence per finding, and a state of its own: new, acknowledged, resolved, accepted risk.

Reports someone can read

PDF and DOCX from the same data and the same charts, on demand on every plan, scheduled and emailed on the higher tiers.

Passive by decision

No credentials tried, no paths probed, no weakness confirmed by exploiting it. The boundary does not move per engagement.

How it works

1
Prove the domain

A TXT record, a well-known file or an email challenge. Until one succeeds, nothing is scanned.

2
Buteo reads what is public

DNS and email posture, mail transport, DNSSEC, subdomains, ports, TLS, headers, cookies, technologies, IP and ASN.

3
Findings, with a lifecycle

Severity, explanation and evidence per finding, and a state you own: new, acknowledged, resolved, accepted risk.

4
The next scan says what changed

Scheduled or on demand. Alertable change is separated from noise and goes by email to whoever needs to know.

5
A report someone can read

PDF and DOCX from the same data and charts, on demand on every plan, scheduled and delivered on the higher tiers.

Three plans

From a single domain to auditing a group. Pricing is on request while the offer settles: tell us how many domains you have and how often you want them scanned, and we will come back with a proposal.

Plan Who it is for What it adds
Freeone domain One verified domain, scanned on demand. DNS and email posture, TLS, headers, subdomains and ports, PDF and DOCX export, 30 days of history, two seats.
Proup to ten domains Anyone who needs to know what changed since yesterday. Continuous monitoring and run-to-run comparison, email alerts, scheduled reports, the DNS record validator, lookalike domains, vulnerability lookup and takeover risk, one year of history.
Enterpriseunlimited A group, a portfolio of brands, or auditing third parties. Daily scans, service and database exposure, related domains and nameserver neighbours, your own branding on reports, API access, two years of history.

The rules that define the product

Verified domains only

There is no way to scan a domain you have not proven from your account. It is a legal and abuse boundary, not a formality.

An honest scanner

Every host Buteo touches can see who is asking and where to write. It honours opt-outs and answers abuse reports.

A score that says what it is

The risk score is an indicative heuristic, and the report labels it as one rather than dressing it up as a standard it is not.

How many domains do you answer for?

Tell us how many and how often, and we will say what the first scan shows and what the second one will tell you.