External Exposure scanner

See what your organisation exposes to the internet.

Run an authorised External Exposure check across the full TCP range from a fixed UK source. See which services are reachable, what needs review, and keep evidence for follow up.

Verified account required. Authorised targets only. No credit card needed.

Explore ScanPosture

Full TCP rangeFixed UK sourceAuthorised checks onlyNo intrusive testingEvidence retained
External ExposureLast check 6 minutes ago

Target

example.com

Observed services

3

  • 443HTTPSObserved
  • 25SMTPNeeds review
  • 3389RDPNot observed

Risk bands

ExpectedNeeds reviewHigh concernInsufficient context

Evidence

Source address recordedChecked ports recordedTimestamp recorded

What a free External Exposure check shows

A check shows which TCP services are reachable from the internet, how ScanPosture classifies the observation, and what evidence was recorded.

01

Full TCP reachability

Every TCP port from 1 to 65535 is checked so exposed services are not missed because they sit outside common port lists.

02

Service context

Observed services are labelled in plain English so you can see whether they look expected, need review, or need urgent attention.

03

Evidence retained

Each check records the target, timestamp, source, observed ports, and service evidence so the result can be reviewed later.

Authorised checks only.

External exposure scanning must be controlled. ScanPosture only runs checks after the user confirms they own, administer, or are authorised to test the target.

Verified account

A verified account is required before scanner use.

Target confirmation

The user must confirm they are authorised to check the target before a job is queued.

Audit trail

The authorisation statement and check metadata are retained with the scan record.

Start free. Upgrade when you need continuous exposure assurance.

The free scanner is designed to give a fast, authorised view of exposure. A ScanPosture subscription adds monitoring, reporting, alerts, deeper history, and Microsoft 365 posture context.

Free exposure check

One authorised check when you need a fast view.

  • Full TCP range check
  • Plain English service classification
  • Recorded evidence
  • Verified account required

Verified free scanner account

Repeat checks with limited history.

  • Limited scan history
  • Limited repeat checks
  • Saved targets
  • Basic evidence review
Most complete

ScanPosture subscription

Continuous exposure assurance with Microsoft 365 posture.

  • Scheduled scans
  • Longer history
  • Reports
  • Alerts
  • Exports
  • Microsoft 365 posture context
  • Governance and evidence workflows

How an External Exposure check works

1

Create or sign in to a verified account

Scanner use requires a verified account.

2

Confirm the authorised target

Confirm that you own, administer, or are authorised to check the domain, host, or IP address.

3

Run the check from a fixed UK source

ScanPosture checks TCP reachability from a known UK source so results are reproducible.

4

Review evidence and next actions

See reachable services, classification, evidence, and what should be reviewed.

From exposed services to evidence.

ScanPosture turns an internet-facing signal into a record you can review, repeat, and report.

External Exposure resultLast checked 6 minutes ago

example.com

3 observed services

  • 443HTTPSObserved
  • 25SMTPNeeds review
  • 3389RDPNot observed
ExpectedNeeds reviewHigh concernInsufficient context

Record

  • Checked from a fixed UK source
  • Timestamp recorded
  • Evidence retained
  • History available with a verified account

Scheduled scans, reports, alerts, and Microsoft 365 posture context come with a ScanPosture subscription.

Built for authorised exposure checks.

ScanPosture External Exposure is for organisations checking assets they own, administer, or are authorised to assess. It performs reachability and safe service detection only.

Allowed

  • Your organisation's domains, hosts, and IP addresses
  • Client assets where you have written authority
  • MSP managed tenants and infrastructure where scanning is authorised

Not allowed

  • Targets you do not own or administer
  • Third party systems without authorisation
  • Testing intended to disrupt, exploit, brute force, or bypass controls

External Exposure checks do not replace penetration testing and do not prove that a service is secure. They show what is reachable from the internet and preserve evidence of that observation.

Know what you are exposing.

Create a verified scanner account and run an authorised External Exposure check in minutes. Upgrade to ScanPosture when you need scheduled checks, reports, alerts, history, and Microsoft 365 posture context.

Verified account required. Authorised targets only. No credit card needed.