The outside view
Buteo reads what your domain already publishes to the internet, from the SPF record to the certificate, from forgotten subdomains to missing headers, and turns it into scored findings with evidence and a lifecycle. Then it scans again and tells you what changed. Nothing to install, no agents, and it never touches your systems: it only scans domains whose ownership has been proven, and it reports a weakness rather than exploiting it.
Ibex is the inside view, the sealed appliance on the network the cloud cannot reach. Buteo is the other one: your domain as anyone on the internet sees it. A buteo is a buzzard, the hawk that circles high and reads the ground below, which is exactly the vantage point it takes.
The surface nobody reviews
Most organisations know what runs inside their infrastructure, and far less about what their infrastructure tells the world. An SPF record ending in a soft fail that was never corrected. A subdomain from a 2019 campaign still pointing at a service that was cancelled. A certificate expiring on a Saturday. A security header lost in a migration.
None of it shows up in an internal inventory, and all of it is visible to anyone who cares to look. When it is found, it is usually found by the wrong person first.
Problems, not reports
Buteo asks what the domain publishes and evaluates it the way a receiving server or a browser would: not whether an SPF record exists, but whether it stops a forged message; not whether DMARC is set, but whether it is rejecting or merely observing.
Every finding carries a severity, an explanation, its evidence and a lifecycle of its own. Run it again and Buteo shows what changed between the two, which is the question that actually matters from the second week onward.
Proven first, passive always
Two rules separate Buteo from a scanner you can point anywhere.
The engine refuses to scan a domain until its ownership is proven: a TXT record, a file at a well-known location, or an email challenge. And it never tries credentials, hunts for forgotten files, probes paths on spec or confirms a weakness by exploiting it. A dangling CNAME is reported, never claimed. A weak cookie is reported, never replayed. The boundary is a product decision with legal consequences, and it does not move because it would be convenient on a particular engagement.
Key features
Ownership proven first
A TXT record, a well-known file or an email challenge. Until one succeeds, the engine refuses to scan.
Email posture that works
SPF resolved in full with its lookup count, DMARC checked for whether it rejects, the DNSSEC chain followed to the root.
TLS, headers and cookies
Protocols and ciphers graded, the certificate chain and its time left, each missing header with what its absence permits.
The perimeter you forgot
Subdomains, dangling CNAMEs open to takeover, reachable ports, IP ranges and ASNs, and lookalike domains registered by others.
What changed since yesterday
Every scan is compared with the last. Alertable change is separated from recurring noise, and the events feed a history.
Findings with a lifecycle
Severity, explanation and evidence per finding, and a state of its own: new, acknowledged, resolved, accepted risk.
Reports someone can read
PDF and DOCX from the same data and the same charts, on demand on every plan, scheduled and emailed on the higher tiers.
Passive by decision
No credentials tried, no paths probed, no weakness confirmed by exploiting it. The boundary does not move per engagement.
How it works
Prove the domain
A TXT record, a well-known file or an email challenge. Until one succeeds, nothing is scanned.
Buteo reads what is public
DNS and email posture, mail transport, DNSSEC, subdomains, ports, TLS, headers, cookies, technologies, IP and ASN.
Findings, with a lifecycle
Severity, explanation and evidence per finding, and a state you own: new, acknowledged, resolved, accepted risk.
The next scan says what changed
Scheduled or on demand. Alertable change is separated from noise and goes by email to whoever needs to know.
A report someone can read
PDF and DOCX from the same data and charts, on demand on every plan, scheduled and delivered on the higher tiers.
Three plans
From a single domain to auditing a group. Pricing is on request while the offer settles: tell us how many domains you have and how often you want them scanned, and we will come back with a proposal.
| Plan | Who it is for | What it adds |
|---|---|---|
| Freeone domain | One verified domain, scanned on demand. | DNS and email posture, TLS, headers, subdomains and ports, PDF and DOCX export, 30 days of history, two seats. |
| Proup to ten domains | Anyone who needs to know what changed since yesterday. | Continuous monitoring and run-to-run comparison, email alerts, scheduled reports, the DNS record validator, lookalike domains, vulnerability lookup and takeover risk, one year of history. |
| Enterpriseunlimited | A group, a portfolio of brands, or auditing third parties. | Daily scans, service and database exposure, related domains and nameserver neighbours, your own branding on reports, API access, two years of history. |
The rules that define the product
Verified domains only
There is no way to scan a domain you have not proven from your account. It is a legal and abuse boundary, not a formality.
An honest scanner
Every host Buteo touches can see who is asking and where to write. It honours opt-outs and answers abuse reports.
A score that says what it is
The risk score is an indicative heuristic, and the report labels it as one rather than dressing it up as a standard it is not.

