Professional Security Intelligence

Uncover. Assess.
Secure.

Automated OSINT and vulnerability scanning for your domains — WHOIS, DNS, SSL/TLS, email security, port discovery, web technology fingerprinting, and CVE detection. Delivered in a detailed report.

Stripe Secured
PCI Compliant
Report in <2hrs
Confidential

Start Your Scan

€50
Your report download link will be tied to this email.
Enter one domain per line — no URLs, just bare domains.
0 / 10
Secure payment via Stripe — we never see your card details

Comprehensive Security Assessment

Your scan runs across 10 intelligence categories using industry-standard tools.

WHOIS & DNS

Domain registration details, expiry dates, nameservers, and complete DNS record enumeration (A, MX, TXT, CNAME, NS).

Stage 1
Email Security

SPF, DKIM (50+ selector checks), DMARC policy, MTA-STS, TLS-RPT, and BIMI — with a scored email security rating.

Stage 2
SSL/TLS Analysis

Certificate validity, weak cipher detection, protocol support (TLS 1.0–1.3), security header audit, and SRI checks.

Stage 2
OSINT Harvesting

Passive intelligence gathering via theHarvester — emails, subdomains, and exposed personnel using Google, Bing, and LinkedIn.

Stage 2
Port & Service Discovery

Full port scan (nmap + RustScan), service version detection, and open service identification across all reachable hosts.

Stage 3
Directory Enumeration

Web path discovery via dirsearch — identifies exposed admin panels, backup files, configuration paths, and sensitive endpoints.

Stage 3
Git Exposure Check

Detects publicly accessible /.git/ repositories that could expose source code, credentials, and commit history.

Stage 3
Vulnerability Assessment

CVE detection via nmap NSE scripts, nuclei templates, nikto, and testssl.sh — with severity ratings and remediation guidance.

Stage 4

How It Works

1
Submit Your Domains

Enter your email and up to 10 domains. Confirm you own or have authorisation to scan them.

2
Pay Securely

One-time payment of €50 via Stripe. Your card details never touch our servers.

3
Receive Your Report

Track progress live. Download your full HTML/PDF report within 2 hours, ready to share with your team.

Most Popular
Domain Intelligence Report
€50 one-time
  • Up to 10 domains
  • WHOIS & DNS analysis
  • SSL/TLS certificate audit
  • Email security (SPF/DKIM/DMARC)
  • OSINT harvesting
  • Port & service discovery
  • Directory enumeration
  • Git repository exposure check
  • CVE vulnerability detection
  • Prioritised remediation guide
  • HTML report (print to PDF)
Start Scan — €50

Terms of Service & Legal Notice

Authorised use only. ReconOSINT is a professional security assessment service. By placing an order, you warrant and agree that:

  • You are the owner of, or hold explicit written authorisation from the owner to perform security scanning on, every domain you submit, and you can produce evidence of that authorisation on request.
  • You will not use this service to attempt unauthorised access to, or disruption of, any computer system. Doing so may constitute an offence under the Computer Misuse Act 1990 (UK), the Criminal Justice (Offences Relating to Information Systems) Act 2017 (Ireland), EU Directive 2013/40/EU, and equivalent legislation in your jurisdiction.
  • Indemnification. You agree to indemnify, defend, and hold harmless ReconOSINT, its operating company, and their officers, employees and contractors from and against any and all claims, demands, losses, liabilities, fines, and costs (including reasonable legal fees) arising out of or related to your use of the service, any scan you initiate, or any breach of these terms — including any scan performed without proper authorisation.
  • Point-in-time, no guarantee. Findings are an automated, non-exhaustive, point-in-time snapshot. The absence of a finding is not a guarantee that no vulnerability exists, and breach / dark-web results rely on third-party data that may be incomplete. The report does not constitute a formal penetration test or a certification of security.
  • Results are provided for informational and remediation purposes only, must be handled as confidential information, and should be independently validated before you act on them. ReconOSINT accepts no liability for actions taken, or not taken, on the basis of a report; you remain responsible for the security of your systems.
  • We may refuse, throttle, or suspend any request at our sole discretion — including, without limitation, scans of government, military, critical-infrastructure, or third-party shared-hosting domains.
  • Payments are non-refundable once scanning has commenced.
  • These terms are governed by the laws of Ireland, and the courts of Ireland have exclusive jurisdiction over any dispute arising from them.

For enterprise agreements, custom scanning, or support: [email protected]