Free outside-in security rating
Free Vendor Security Score
Check any company's external security posture in seconds. Enter a domain and receive an outside-in score across email protection, reachable services, published vulnerabilities, and web hardening.
No sign-up. The scan only reads publicly observable data and never touches the target's internal systems.
What the score measures
Email security
SPF, DKIM, DMARC, and MTA-STS records, which decide whether anyone can send email that claims to come from the domain.
Network security
Which service ports answer on the public internet, whether database engines are exposed, and whether edge protection sits in front of the site.
Application hardening
The security response headers a browser receives, version disclosure, and clickjacking protection.
TLS and encryption
Whether valid certificates are served on the domain and its www address, and whether browsers are told to always use HTTPS.
Vulnerability exposure
Known published vulnerabilities for the services that answer externally, weighted by severity.
Frequently asked questions
Is the vendor security score really free?
Yes. The score is free with no account and no payment. Enter a domain and the scan runs in seconds.
What does the score measure?
It measures externally observable security posture: the same outside-in signals a security team or an attacker can see without any access to internal systems.
How is the score calculated?
Each collected fact becomes a signal with points. Signals are grouped into five categories, and the score is the share of available points that were earned. Categories that could not be assessed are excluded and the score is rescaled across the rest.
Can an external score replace an assessment?
No. External signals are incomplete by nature. Some organizations deliberately run decoy services that can appear as risk signals. Always corroborate a score with direct assessment and evidence before drawing conclusions.
What should we do after a bad score?
Start with the email security records, because they are the cheapest to fix and stop direct spoofing. Then close exposed service ports and add the missing web headers. Dephiant turns the findings into a prioritized remediation plan with a quantified financial risk view.
A score is a starting point, not a conclusion
Dephiant Consulting Inc. is a global cybersecurity advisory. We turn outside-in findings into a prioritized remediation plan, a quantified financial risk view, and audit-ready evidence. If a vendor or your own domain scored poorly, tell us and we will review it with you.