Articles on: Security Scan

Security Scan: DNS, E-Mail & Web Vulnerability Checks

The AutoPhish Security Scan gives you an outside-in view of your organization's security posture. It automatically checks your domains for publicly visible risks – from weak e-mail authentication to known web vulnerabilities – and presents the results with clear recommendations in the AutoPhish Security Center.


Many attacks start with simple, publicly detectable weaknesses: a domain that can be abused for spoofing, an exposed web service, or an outdated component. The Security Scan helps you find and fix these issues before attackers do.


What the Security Scan checks


1. DNS & E-Mail Security


This check verifies that your domain is protected against e-mail spoofing and impersonation:


  • SPF, DKIM and DMARC configuration
  • DMARC policy strength and reporting setup
  • MX and general domain configuration
  • Weak or missing e-mail authentication policies
  • Change detection – you see when relevant DNS records change


Why it matters: attackers routinely test whether a domain can be abused for spoofing and impersonation. Correct SPF, DKIM and DMARC settings protect your brand, make e-mail abuse harder, and also improve deliverability of your legitimate mail.


2. Web & Vulnerability Scan


This check examines your publicly reachable web services and highlights:


  • Known vulnerabilities (CVEs) in exposed software
  • Common web risks such as XSS, SQL injection and SSRF
  • Misconfigurations and unnecessarily exposed services
  • Technology fingerprints that indicate outdated or risky components


You stay in control: web scans are disabled by default and can be explicitly enabled per domain.


Your results in the Security Center


All findings are collected in the AutoPhish Security Center – one central overview instead of raw data:


  • Security Score per domain
  • DNS health overview
  • Findings grouped by severity (critical to info)
  • Concrete, actionable recommendations for every finding
  • Scan history per domain, so you can track improvements over time


You can manage individual findings and mark them as reviewed, resolved, or false positive. Critical and high findings can be reported automatically, so the right people know right away.


Good to know


  • External view only: the scan looks at your infrastructure the way an outsider does. No agents, no credentials and no access to internal systems are required.
  • Automated & repeatable: scans run automatically, so you always have an up-to-date picture instead of a one-off snapshot.
  • Not a penetration test: the Security Scan is a fast, repeatable early-warning system for publicly visible risks. It complements, but does not replace, an in-depth penetration test.


Who is it for?


  • SMEs without a dedicated security team
  • IT and security managers who want a repeatable external check
  • MSPs and IT service providers managing multiple customer domains
  • Compliance and risk owners who need evidence of regular security checks (e.g. for NIS2)


Questions about your scan results? Reach out via chat – we are happy to help.

Updated on: 17/07/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!