Publicly observable checksSPFDMARCDKIMNo tenant sign-in

Check the Microsoft 365 protections
visible from the internet

Enter a business domain to review public DNS and email-security signals. This scan does not sign in to Microsoft 365 and cannot see internal tenant configuration.

No account or PowerShell required
Public DNS and email settings only
No tenant access required
Free external exposure scan
Public DNS and email check
No account needed. We query public DNS and email-security records only; this is not an internal tenant assessment. Need the inside view? See the Microsoft 365 Security Assessment →
Checking DNS records…

External exposure scan results

0 / 100
Scanning…
Five public email-domain checks — not an internal tenant assessment

This is the outside view. Internal controls require tenant access.

The paid Microsoft 365 Security Assessment reviews applicable controls inside your environment, validates the findings with an analyst, and delivers executive and technical reports plus a prioritized action register. Remediation implementation is scoped separately.

Paid service — Microsoft 365 Security Assessment

Need the inside-the-tenant
security view?

The assessment selects the applicable subset from a 400+ Microsoft 365 control library, adds analyst validation, and turns the findings into a prioritized plan your team can use.

Scoped
Identity & Microsoft Entra ID
Users, groups, roles, admin accounts, app registrations, service principals
Excess Global Administrator assignments
Stale guest accounts
MFA gaps for administrator roles
Scoped
Conditional Access
Policy gaps, legacy authentication, location bypass, sign-in risk controls
Legacy authentication not blocked
No risk-based Conditional Access policy
Report-only policies
Scoped
Microsoft Defender for Office 365
Anti-phishing, safe links, safe attachments, zero-hour auto purge
Safe Links disabled
Impersonation rules weak
DKIM not enforced
Scoped
Exchange Online
Mail flow rules, relay, journaling, mailbox permissions, transport rules
Mail flow safeguards
Overpermissioned delegates
Journaling unconfigured
Scoped
SharePoint & OneDrive
External sharing, link expiry, guest access, DLP policies, sensitivity labels
Anyone links enabled
No link expiry
External sharing unrestricted
Scoped
Microsoft Teams
Guest access, anonymous meetings, third-party app permissions, channels
Anonymous join enabled
External apps uncontrolled
Guest messaging allowed
Scoped
Microsoft Intune & Devices
Compliance policies, encryption, OS patch level, jailbreak detection, MAM
Non-compliant devices in use
Encryption not enforced
No MDM compliance CA
Scoped
Email Auth & DNS
SPF, DMARC, DKIM, MX, DNSSEC, mail-flow and domain protections
DMARC policy = none
SPF too permissive
DKIM key not rotated
400+
applicable controls reviewed with read-only access
CIS v8 NIST 800-53 CMMC 2.0 SOC 2 CISA SCuBA ISO 27001 HIPAA
Choose the right depth

A public scan is useful.
It is not the whole tenant.

Use this free tool for an outside-in signal. Choose the Microsoft 365 Security Assessment when you need a defensible, analyst-reviewed view of identity, access, collaboration, device, and security configuration.

Free External Exposure Scan
Public signals only
No sign-in or tenant access
DNS and email-security protections
~Cannot evaluate internal Microsoft 365 settings
Microsoft 365 Security Assessment
From $3,500
Applicable controls selected from a 400+ control library
Executive report, technical report, and action register
Stakeholder readout; remediation implementation scoped separately
Frequently asked questions

Know what the free scan can—and cannot—show.

What does the free External Exposure Scan check?

It checks public SPF, DMARC, Microsoft 365 DKIM selector CNAME records, DNSSEC validation, and mail-routing observations. The indicator is directional and is not a vulnerability scan or certification.

Does this scan assess settings inside Microsoft 365?

No. It does not authenticate to a tenant or inspect internal identity, Conditional Access, endpoint, collaboration, or Microsoft Defender settings. Those require an authorized, separately scoped assessment.

Need the full tenant view?

The Microsoft 365 Security Assessment combines read-only evidence collection with analyst validation, executive and technical reporting, a prioritized action register, and a stakeholder readout.

Read-only evidence collection
Analyst-reviewed action register
From $3,500 · implementation scoped separately

From signal to decision

Need an analyst-reviewed Microsoft 365 security plan?

Share the business question, environment outline, and timing. No tenant access or sensitive export is needed to start.