Graded recon, and a report for clients

Graded recon, and a report for clients

Recon and client work look like different problems until you notice they need the same thing: a fast, honest read of what a domain exposes to the internet, and a way to write it down that somebody else will believe.

ClickScan is now open in beta, to everyone, with no invitation and no waiting list.

What runs on a target you do not own

The passive checks — TLS and encryption, HTTP security headers, email authentication, subdomain discovery and the look-alike domain monitor — read public DNS, public certificate logs and the target's own published records. Nothing is sent to the target that an ordinary visitor would not send, so they run against an authorised programme target as readily as against your own domain. Findings export as STIX 2.1 or YARA.

The Brand Impersonation Monitor is the one worth a look. It generates thousands of variations of a name — look-alike characters, typos, compound names, alternative endings — and resolves each against DNS, mail servers, certificate transparency and live content. Every candidate lands in exactly one verdict.

A Brand Impersonation deep sweep: five look-alike domains found, with a coverage account showing 11,453 variations built and 11,447 checked, and an explicit list of what the sweep did not establish

Look at the bottom of that report. The coverage figures account for the whole candidate set, including what could not be looked up, what was skipped, and what was discarded because the answer proved nothing. That is the difference between "nothing found" as a claim and "nothing found" as something you can check.

What needs the asset proven yours

The port scan, the live spoofing test and the breach lookup need the asset proven yours first — by a DNS TXT record, a file at /.well-known/, a code emailed to an address at the domain, a callback from the IP, or reverse DNS.

That is not a licensing tier, it is the line between reading what is published and touching a host. Worth knowing before you spend a credit expecting otherwise — those checks are for your own estate rather than a programme's.

If your clients are the target audience

Every check is graded A+ to F, and the report names the finding that drove the grade, how severe it is, and whether we proved it ourselves or read it from a published record. That is the difference between a scanner output and something you can put in front of a non-technical client — and on a paid account the downloadable PDF carries your logo and colour instead of ours.

Anything a third party observed rather than ClickScan is shown in the report — it is what an attacker learns for free — but it is never allowed to move the grade, and it is counted separately from the findings you are accountable for.

What you can run for nothing

Every new account gets five starter credits. The certificate check, the security-headers check and the email-authentication check cost one credit each, so those three run on a domain twice over before you have spent anything. The Brand Impersonation Monitor and subdomain discovery are five credits — one full sweep on the house. Seven of the eleven checks need no ownership proof at all.

Reports display in full on screen on a free account; downloading one as a PDF is a paying-account feature.

What it costs after that

Pay-as-you-go credits. No subscription, no per-seat fee. Credits you buy never expire; free credits last twelve months and are spent first. A scan that fails is refunded, and a check with nothing to test is graded "not applicable" and refunded too. Sign-in is passwordless: a one-time code to your email address. No card to start.

A launch promotion is running on the credit packs right now: 20% off Growth, 10% off Pro and 20% off Scale. Prices are shown in the app before you pay.

How the referral works

Every account gets a referral code, under Referrals in the sidebar. It is worth spelling out how it pays, because most schemes pay on sign-up and this one does not.

  • Someone registers with your code. They get the five starter credits every new account gets, and their first checks cost nothing.
  • On their first purchase, you both get ten more. The referral converts when they first top up — not at sign-up. The free trial stays free, and the bonus arrives when the tool has proved worth paying for.
  • Signing up alone converts nothing for either side — deliberately, so the scheme cannot be farmed.

Start free at app.clickscan.ai. The detail is at clickscan.ai/for-freelancers/ and clickscan.ai/for-researchers/.

← Back to blog