DNS & email records
MX, SPF, and DMARC visibility for spoofing and delivery risk awareness.
Public Exposure Scanner
occhira helps teams understand what is publicly visible about their infrastructure without penetration testing, exploitation, or intrusive access.
Only scan domains you own or have permission to assess.
Passive external assessment. Results usually appear within a minute.
Passive checks only: no exploitation, no authenticated testing, no intrusive scanning.
Each module runs independently. Failures in one check do not stop the rest of the assessment.
Public DNS and email authentication records (MX, SPF, DMARC).
Certificate validity and HTTPS configuration from outside.
Browser protections such as HSTS, CSP, and clickjacking controls.
Passive fingerprinting of public-facing components.
Public crawl rules and path visibility from robots.txt.
Validated hostnames for your brand. Verified Scan becomes available after domain verification.
We observe what is already public: DNS, TLS, headers, technology fingerprinting, and robots.txt. No exploitation and no authenticated access.
The report reflects what someone on the internet can learn before logging in or touching your internal systems.
Findings are written for owners and IT partners: severity, evidence, and practical next steps.
occhira is not a penetration testing platform, red team tool, or attack framework. It is an exposure awareness product.
Straight answers about passive external assessments.
occhira runs passive external checks: DNS and email records, SSL/TLS configuration, HTTP security headers, technology fingerprinting, and robots.txt analysis. Subdomain discovery is included in Verified Scan. Verified Scan becomes available after domain verification. It does not exploit vulnerabilities or access your internal systems.
No. occhira is a passive exposure assessment. It helps you understand what is visible from the internet and prioritise improvements. It is not a substitute for a formal penetration test or red team engagement.
Enter a domain on the homepage, start the scan, and wait for the assessment to complete. You receive a structured report with findings, severity, and recommended fixes. No account is required.
Yes. When a scan completes, you can download a PDF exposure report suitable for sharing with your IT partner or leadership team.
Business owners, security leads, and IT partners who need a clear picture of external exposure without running intrusive tests. Always ensure you have permission to assess the domains you scan.
Domain verification will enable Verified Scan capabilities such as subdomain discovery, plus continuous monitoring and deeper assessments. The current public MVP focuses on one-off passive assessments and PDF export.
Reach out by email while the product is in public MVP.
Public Exposure Scanner
See what attackers can see.
Run a passive scan from the homepage. No account required in this MVP.
Scan a domain→Stage
Public MVP
Method
Passive only
Reports
Web + PDF
Accounts
Not available yet
© 2026 occhira. Passive exposure assessments only, not a penetration test.
occhira.com