Check the Microsoft 365 protections visible from the internet
Enter a business domain to review public DNS and email-security signals. This scan does not sign in to Microsoft 365 and cannot see internal tenant configuration.
No account or PowerShell required
Public DNS and email settings only
No tenant access required
Free external exposure scan
Public DNS and email check
No account needed. We query public DNS and email-security records only; this is not an internal tenant assessment.
Need the inside view?See the Microsoft 365 Security Assessment →
Checking DNS records…
External exposure scan results
0/ 100
—
Scanning…
Five public email-domain checks — not an internal tenant assessment
This is the outside view. Internal controls require tenant access.
The paid Microsoft 365 Security Assessment reviews applicable controls inside your environment, validates the findings with an analyst, and delivers executive and technical reports plus a prioritized action register. Remediation implementation is scoped separately.
Paid service — Microsoft 365 Security Assessment
Need the inside-the-tenant security view?
The assessment selects the applicable subset from a 400+ Microsoft 365 control library, adds analyst validation, and turns the findings into a prioritized plan your team can use.
Scoped
Identity & Microsoft Entra ID
Users, groups, roles, admin accounts, app registrations, service principals
A public scan is useful. It is not the whole tenant.
Use this free tool for an outside-in signal. Choose the Microsoft 365 Security Assessment when you need a defensible, analyst-reviewed view of identity, access, collaboration, device, and security configuration.
Free External Exposure Scan
Public signals only
✓No sign-in or tenant access
✓DNS and email-security protections
~Cannot evaluate internal Microsoft 365 settings
Microsoft 365 Security Assessment
From $3,500
✓Applicable controls selected from a 400+ control library
✓Executive report, technical report, and action register
It checks public SPF, DMARC, Microsoft 365 DKIM selector CNAME records, DNSSEC validation, and mail-routing observations. The indicator is directional and is not a vulnerability scan or certification.
Does this scan assess settings inside Microsoft 365?
No. It does not authenticate to a tenant or inspect internal identity, Conditional Access, endpoint, collaboration, or Microsoft Defender settings. Those require an authorized, separately scoped assessment.
Need the full tenant view?
The Microsoft 365 Security Assessment combines read-only evidence collection with analyst validation, executive and technical reporting, a prioritized action register, and a stakeholder readout.