Business
Individual
Partners
Intelligence
How we work
Sign in Check my firm
Guide · Updated 30 Sep 2026

What a firm exposes from outside

Everything a firm exposes to the internet can be read from outside, without logging in to anything. The industry calls this external attack surface management. Here is what it covers, in plain words.

Updated 30 Sep 2026Reading time 6 minBy LeakTrace

The outside view

Every firm has a footprint on the internet: the domains it owns, its email settings, its website, and systems it may have forgotten, such as an old client portal or a test site. Your firm’s addresses in breach data are part of it too. Anyone can read this footprint, including someone planning a fraud.

What is read

  • Email and domain settings: SPF, DKIM and DMARC records, which decide whether email in your name can be forged.
  • Your firm’s addresses: presence in monitored breach databases and on paste sites.
  • Website: what its responses reveal about its software, its security headers and its certificate.
  • Lookalike domains: names one character off yours, and whether they can send email.
  • Public records and website code: business registrations that name the firm, and keys left in its own website code.

Why a list of known systems is not enough

An internal review starts from the systems the firm knows about. An outside read starts from the domain and finds what is connected to it, which often includes systems nobody remembered: a site set up by a former supplier, or a domain that still points at a service the firm stopped using.

Putting findings in order

Not every finding comes first. A readable password for a current staff address, or a domain whose email can be forged, comes before a missing website header. Each finding should say what it is, why it matters and who fixes it.

How LeakTrace does it

An External Cybersecurity Assessment reads this outside view once, dates it, and every finding is human-verified before the firm sees it. Every finding carries the command or public source that proves it, and a step-by-step fix the firm’s IT provider makes. Forged-email protection is switched on in one click where we can reach the firm’s DNS host, with the exact records to paste where we can’t. Monitoring re-reads email settings, look-alike domains and new host names every hour, and everything else every day.

A check you can run now

nslookup -type=txt _dmarc.yourfirm.ca

If nothing comes back, there is no DMARC policy. If it says p=none, forged email in your name is still delivered.