Back to 360 Playbooks
Read a Company Reportintermediate

Attack Surface, Domain, and Recon Findings

Read exposure, DNS/mail health, and severity-ranked recon findings on an unlocked profile.

SecurityAudit360 Team
6/25/2026
6 min read
attack-surfacedomainreconfindings

Attack Surface, Domain, and Recon Findings

Who this is for: Analysts doing technical vendor review on unlocked profiles.

What you'll learn:

  • Recon finding categories and severity
  • Domain, DNS, and email signals
  • Attack surface exposure priorities

Recon findings

Findings group by theme (infrastructure, email, DNS, etc.) with critical → informational severity.

Prioritize:

  1. Critical/high on internet-facing assets
  2. Mail spoofing gaps (missing DMARC)
  3. Certificate and TLS issues on production hosts
  4. Informational items last

Each finding ties to evidence in the report — use for vendor questionnaires.

Domain & email

Watch for:

  • SPF / DKIM / DMARC gaps → phishing/spoof risk
  • Certificate expiry or weak ciphers
  • Subdomain sprawl → larger attack surface

Attack surface

Shows discovered hosts, open ports, services, and technology signals.

Focus on unexpected admin interfaces, databases, or remote access exposed publicly.

Link to ratings

Severe findings drive score drops — see what affects your rating.

After vendor remediation, request re-scan (Pro+ monthly allowance) or re-audit ticket.

Plan requirements

Full detail requires unlock (Pro+). Public views show summaries only.

Related articles

Still stuck? Support

Last updated: 6/25/2026