Posture summary
Email authentication
SPF ✗ DMARC ✗ DKIM ✗ DNSSEC ✗TLS / certificate
No valid TLSInternet exposure
1 open ports 0 KEVBreach metadata
0 public breachesDomain & hosting
9 public hostnames registered 2009 AS10439 · CARINET - CariNet, Inc. no blocklist hitsPublic attack surface (9 hostnames in Certificate Transparency)
Hostnames this organization published in public TLS certificates. Passive OSINT — nothing was scanned.
The hostname inventory — which forgotten hosts exist and where — is part of the complete audit for this domain.
Lookalike domains (9 registered of 63 checked)
Registered permutations of this domain. Existence is a fact, not an accusation — ownership and intent are not assessed. Those able to receive mail are the ones usable for invoice fraud and phishing.
| Domain | Type | Mail-capable |
|---|---|---|
| ims-sc.com | transposition | yes |
| is-sc.com | omission | yes |
| ism-ac.com | keyboard | yes |
6 further registered lookalike(s), 7 of them able to receive mail. The full list, with mail capability for each, is part of the complete audit.
Recommendations
-
highEnforce DMARC
No enforcing DMARC policy was observed. Publish a DMARC record and move to p=quarantine then p=reject to reduce spoofing.
-
highPublish SPF
No SPF record was observed. Publish one listing authorized senders.
-
mediumEnable DKIM
No DKIM record was found on common selectors. Enable DKIM signing.
-
mediumEnable DNSSEC
DNSSEC signing was not detected for this domain.
-
highEnable valid HTTPS
No valid TLS was observed on port 443.
-
highMonitor lookalike domains
7 registered lookalike domain(s) can receive mail, which is what makes them usable for invoice fraud and credential phishing. Monitor them and consider defensive registrations.
-
highGet a full security audit
Multiple exposures were detected. A professional audit can prioritize remediation.
Refresh this report
Re-run a live analysis or generate a full downloadable audit.
Open live reportAll information is aggregated from public sources for awareness only and does not constitute an accusation or a security assessment. No personal data or credentials are published.