Passive exposure scan

Public Exposure Scanner

See what attackers can see.

occhira helps teams understand what is publicly visible about their infrastructure without penetration testing, exploitation, or intrusive access.

Scan Domain

Only scan domains you own or have permission to assess.

Passive external assessment. Results usually appear within a minute.

  1. 01Enter a domain
  2. 02Run a passive scan
  3. 03Receive a professional exposure report
01 / Capabilities

What we assess

Passive checks only: no exploitation, no authenticated testing, no intrusive scanning.

01

DNS & email records

MX, SPF, and DMARC visibility for spoofing and delivery risk awareness.

02

SSL / TLS posture

Certificate validity and transport configuration from the public internet.

03

HTTP security headers

HSTS, CSP, and browser hardening signals on your public site.

04

Technology fingerprinting

Passive detection of frameworks, CMS, and common stack components.

05

Robots.txt analysis

Public crawl rules and disallowed paths from robots.txt.

06In Development

Subdomain discovery

Public hostname mapping. Verified Scan becomes available after domain verification.

07Coming Soon

Continuous monitoring

Scheduled re-scans and change detection for verified domains.

02 / Modules

Scan modules

Scanner module

DNS analysis

Public DNS and email authentication records (MX, SPF, DMARC).

01
Scanner module

SSL / TLS review

Certificate validity and HTTPS configuration from outside.

02
Scanner module

Security headers

Browser protections such as HSTS, CSP, and clickjacking controls.

03
Scanner module

Technology stack

Passive fingerprinting of public-facing components.

04
Scanner module

Robots.txt

Public crawl rules and path visibility from robots.txt.

05
Verified ScanIn Development

Subdomain discovery

Validated hostnames for your brand. Verified Scan becomes available after domain verification.

06
03 / Approach

How occhira works

01 / PASSIVE

PASSIVE ONLY

We observe what is already public: DNS, TLS, headers, technology fingerprinting, and robots.txt. No exploitation and no authenticated access.

02 / EXTERNAL

EXTERNAL VISIBILITY

The report reflects what someone on the internet can learn before logging in or touching your internal systems.

03 / CLEAR

CLEAR POSTURE

Findings are written for owners and IT partners: severity, evidence, and practical next steps.

04 / RESPONSIBLE

RESPONSIBLE SCOPE

occhira is not a penetration testing platform, red team tool, or attack framework. It is an exposure awareness product.

04 / Questions

Frequently asked questions

Straight answers about passive external assessments.

occhira runs passive external checks: DNS and email records, SSL/TLS configuration, HTTP security headers, technology fingerprinting, and robots.txt analysis. Subdomain discovery is included in Verified Scan. Verified Scan becomes available after domain verification. It does not exploit vulnerabilities or access your internal systems.

No. occhira is a passive exposure assessment. It helps you understand what is visible from the internet and prioritise improvements. It is not a substitute for a formal penetration test or red team engagement.

Enter a domain on the homepage, start the scan, and wait for the assessment to complete. You receive a structured report with findings, severity, and recommended fixes. No account is required.

Yes. When a scan completes, you can download a PDF exposure report suitable for sharing with your IT partner or leadership team.

Business owners, security leads, and IT partners who need a clear picture of external exposure without running intrusive tests. Always ensure you have permission to assess the domains you scan.

Domain verification will enable Verified Scan capabilities such as subdomain discovery, plus continuous monitoring and deeper assessments. The current public MVP focuses on one-off passive assessments and PDF export.

Still have questions?

Reach out by email while the product is in public MVP.

Product

  • Passive domain scans
  • Exposure PDF reports
  • Monitoring (Coming Soon)

Assessments

  • DNS & email
  • TLS & headers
  • Technology fingerprinting
  • robots.txt analysis
  • Subdomain discovery (Verified Scan)

Company

Contact

occhira

Public Exposure Scanner

See what attackers can see.

Run a passive scan from the homepage. No account required in this MVP.

Scan a domain→

Stage

Public MVP

Method

Passive only

Reports

Web + PDF

Accounts

Not available yet

© 2026 occhira. Passive exposure assessments only, not a penetration test.

occhira.com