Pentestr
Security check

External attack surface scan for client websites

Pentestr scans the public surface that attackers, clients, and security reviewers can see without logging in.

Audience

Agencies, MSPs, and dev teams responsible for public client websites.

Pain

Public exposure can change after deployments, DNS updates, hosting migrations, and rushed fixes.

Outcome

A quick picture of visible risk with prioritized remediation.

Public exposure changes constantly

A website's public surface is not static. Infrastructure, dependencies, DNS, and hosting changes can introduce visible gaps after launch.

Focus on what can be seen from outside

Pentestr is intentionally external. It checks what is reachable without credentials, which makes it fast and safe for authorized client workflows.

Use it as a first line of defense

External scans catch common visible problems early and help teams decide when deeper manual testing is needed.

What Pentestr checks

Public TLS configuration
HTTP response headers
Firewall and WAF signals
Technology fingerprints
Open ports
SPF, DKIM, and DMARC
Nuclei findings

Questions

What is an external attack surface scan?

It is a scan of publicly reachable website and domain exposure, such as TLS, headers, ports, WAF, DNS email records, and known issues.

Does it scan private data?

No. Pentestr focuses on public exposure and does not inspect authenticated private application content.

Subscribe on