Continuous Threat Exposure Management

We index the internet. One platform for external security.

The domains you register, the certificates you issue and the passwords employees save all leave traces, and so do your vendors and the lookalikes built to copy you. Deepinfo indexes those traces continuously and shows your team which ones are exposures, before someone else reads them.

Today so far (UTC), from our index 66,703 new domains registered 747 CVEs published 3 added to CISA KEV Internet insights

Among the 10,000+ organizations working from Deepinfo data

  • Turkish Airlines
  • Turkcell
  • Aselsan
  • Wiley
  • Albaraka
  • Türksat
  • Havelsan
  • Tüpraş

Map everything you own on the internet. Especially what you forgot.

Start from one domain. The platform discovers the subdomains, IP addresses, certificates, open ports and technologies behind it, then keeps scanning all of them. Findings arrive scored, with evidence your team can hand to an owner.

ROOT DOMAINSUBDOMAIN IP ADDRESSWHAT IT EXPOSES acme.examplewww.acme.example198.51.100.10443/tcp · TLS 1.3nginx 1.25mail.acme.example198.51.100.1225/tcp · SMTPMX · SPF recordapi.acme.example198.51.100.40Certificate expires in 6 daysMEDIUMvpn-legacy.acme.exampleNOT IN INVENTORY203.0.113.243389/tcp · RDP openCRITICALstaging.acme.example203.0.113.7Apache httpd 2.4.49HIGHCVE-2021-41773 · KEVCRITICALshop.acme.example198.51.100.77PHP 7.4 · end of lifeHIGHblog.acme.example192.0.2.15Login page · HTTP 200

acme.example

  1. www.acme.example198.51.100.10

    • 443/tcp · TLS 1.3
    • nginx 1.25
  2. mail.acme.example198.51.100.12

    • 25/tcp · SMTP
    • MX · SPF record
  3. api.acme.example198.51.100.40

    • Certificate expires in 6 daysmedium
  4. vpn-legacy.acme.example203.0.113.24

    Not in inventory

    • 3389/tcp · RDP opencritical
  5. staging.acme.example203.0.113.7

    • Apache httpd 2.4.49high
    • CVE-2021-41773 · KEVcritical
  6. shop.acme.example198.51.100.77

    • PHP 7.4 · end of lifehigh
  7. blog.acme.example192.0.2.15

    • Login page · HTTP 200

Layer by layer

Scanall checked
www.acme.example198.51.100.10
  1. WHOIS registrar · renews in 41 days
  2. IP WHOIS AS64500
  3. DNS A 198.51.100.10 · MX mail.acme.example
  4. SSL Medium*.acme.example · expires in 6 days
  5. Ports 443/tcp · TLS 1.3
  6. Web data nginx 1.25 · login page
  7. HTTP 200
Every layer checked

In the platform

  • All assets 1,562
  • Domains 3 (selected)
  • Subdomains 1,312
  • IP addresses 247

Domains

  • grade B acme.example (opened on its record)
    • grade A www.acme.example
    • grade B shop.acme.example
    • grade C vpn.acme.example
    • grade A mail.acme.example
    • 1,280 more
  • grade A acme-eu.example
  • grade C acme-labs.example

grade B acme.example

Last check 2 hours ago

  • Overview (selected)
  • Issues
  • Subdomains
  • Technologies
  • Open ports
  • Vulnerabilities
  • Asset info

Info

IP addresses

  • 203.0.113.10
  • 203.0.113.11
  • 203.0.113.12
  • +5 more

Insights

Issues
38
Subdomains
1,284
Technologies
23
Open ports
46
Vulnerabilities
7

Find the domains built to look like you.

A convincing phishing page needs a convincing address. The platform matches newly seen domains against your brand names, down to letters from other alphabets that the eye cannot tell apart. When one resolves, your team sees its DNS, certificate and HTTP evidence and can request a takedown.

Candidates are generated in your browser from the name you type. Nothing is sent, and a candidate is not a claim that the domain exists.

Same nameThe name itself, on another TLD
acme.testacme.invalid
Name insideThe name inside a longer label
acme-login.examplelogin-acme.exampleacme-verify.example
TypoOne edit away: a dropped, doubled, swapped or mistyped letter
ace.exampleacem.exampleacrne.example
Typo insideA typo inside a longer label
login-ace.exampleacem-verify.example
Lookalike lettersLetters swapped for ones that look identical
аcme.examplexn--cme-5cd.exampleaсme.examplexn--ame-4ed.exampleacmе.examplexn--acm-tdd.example
Lookalike letters insideLookalike letters inside a longer label
аcme-login.examplexn--cme-login-zyh.examplelogin-aсme.examplexn--login-ame-13h.example
Lookalike and typoA typo and a lookalike letter together
aсe.examplexn--ae-omc.exampleaсem.examplexn--aem-4ed.example
Lookalike and typo insideBoth, inside a longer label
aсe-verify.examplexn--ae-verify-v3h.examplesecure-aсem.examplexn--secure-aem-jwi.example
lookalike character typo added word xn--what the browser resolves

Your vendors’ exposures are yours too.

A questionnaire tells you what a supplier believes about itself. The platform scans each third party with the engine and layers it runs on your surface, and scores them all on one scale. When a vendor slips, you see it in the next scan, not the next annual review.

A cloud-hosting.example A cdn-provider.example D payroll-partner.example SCORE FELL B → D · RDP EXPOSED B logistics-co.example C law-firm.example C call-center.example B marketing-agency.example B subsidiary-eu.example A crm-saas.example acme.example

acme.example and its third parties

  1. Dpayroll-partner.example Score fell B → D · RDP exposed
  2. Acloud-hosting.example
  3. Acdn-provider.example
  4. Blogistics-co.example
  5. Claw-firm.example
  6. Ccall-center.example
  7. Bmarketing-agency.example
  8. Bsubsidiary-eu.example
  9. Acrm-saas.example

Under every module is an index we built.

Many platforms rent their view of the internet. We collect ours, resolve it and keep it with its history. That data powers each module, and your analysts and developers can query it directly.

  1. 01Collect

    Collected and monitored

    • Domain registrations and WHOIS
    • DNS records
    • SSL certificates
    • Port scansTCP · UDP
    • Web data and HTTP
    • Breach data, infostealer logs, dark web sources
  2. 02Process

    Resolved, enriched, matched, scored

    • Resolve every record and keep its history
    • Enrich every CVECVSS · EPSS · CISA KEV
    • Match findings to your domains, people and brands
    • Score and prioritize
  3. 03Present

    What your team works from

    • The modules EASMCTIBRPTPRMDSI
    • Issues that move through their states
    • Reports and notifications
    • The REST API
400M+ domains

Registered domains across every TLD, with registration, WHOIS history and daily deltas.

Domain Search · Feeds · WHOIS

2B+ subdomains

Subdomains discovered and resolved to the IP addresses they point to.

Subdomain Finder · Feeds

200B+ DNS records

Every observed DNS record, kept with its history, so infrastructure can be traced back in time.

DNS Lookup · DNS History · Reverse IP · Reverse MX · Reverse NS

30B+ SSL certificates

Certificates collected and indexed. The names a certificate covers often reveal hosts nobody announced.

SSL Lookup

Query it

One REST API over the whole index: lookups, reverse lookups, history, discovery and vulnerability search.

Request

curl "https://api.deepinfo.com/v1/lookup/dns?domain=deepinfo.com&type=A,MX" \
  -H "apikey: $DEEPINFO_API_KEY"

Response

200 OK · application/json
{
  "fqdn": "deepinfo.com",
  "requested_types": ["A", "MX"],
  "responses": [
    {
      "type": "A",
      "conn_status": "success",
      "rcode": "NOERROR",
      "values": ["104.26.10.21", "104.26.11.21", "…"],
      "raw": "deepinfo.com. 300 IN A 104.26.11.21\n…",
      "server": "8.8.8.8"
    },
    {
      "type": "MX",
      "conn_status": "success",
      "rcode": "NOERROR",
      "values": ["1 aspmx.l.google.com", "5 alt1.aspmx.l.google.com", "…"],
      "…": "…"
    }
  ],
  "servers": ["8.8.8.8"],
  "check_date": "2026-09-22T12:25:59Z"
}

Some of it is already out there.

Breach dumps, infostealer logs, dark web forums and markets. The platform reads them for your domains, your employees and your customers, and ties each finding to a device, an account or a person your team can act on.

HWID          ---1
UserName      j.
MachineName   ACME-LT-2
OS            Windows 11 Pro x64
Locale        en-GB

[Passwords]   41 total3
  URL  https://sso.acme.example/login
  USER j.@acme.example
  PASS 
  URL  https://vpn-legacy.acme.example
  USER j.
  PASS 

[Cookies]     1,208 total · 36 sensitive4
[Autofill]    312 entries
[Tokens]      4
SamePassword  63%5
  1. 1

    Hardware ID

    Ties every credential to one physical device, so a single infection is counted once.

  2. 2

    User and system

    Machine name, OS and locale, enough to find the device in your own fleet.

  3. 3

    Saved passwords

    Every login the browser remembered, including the ones for your own domains.

  4. 4

    Session cookies

    Sensitive cookies can skip the password and the MFA prompt entirely.

  5. 5

    Same-password rate

    How often one password is reused across the sites in the log.

Every finding gets a score, an owner and a state.

Vulnerabilities are ranked with CVSS, EPSS and CISA KEV together, so the top of the list is what attackers are most likely to use. Each issue then moves from state to state until a rescan confirms it is gone. If the signal comes back, the issue reopens by itself.

newly detectedunresolvedmarked as resolvedverified resolvedre-scan confirmsreappearedsignal returnsrisk acceptedignoredmarked as false positivenot applicableclosed by decision, kept on record

The path

  1. newly detected
  2. unresolved
  3. marked as resolved
  4. verified resolvedre-scan confirms

If the signal returns

verified resolved → reappeared → unresolved

Closed by decision, kept on record

risk acceptedignoredmarked as false positivenot applicable

Around each issue

Notifications

New, reappeared and changed findings, delivered instantly, hourly, daily, weekly or monthly.

Reports

From the executive summary to issue detail, as PDF, on demand or on a schedule.

Compliance mapping

Each issue classified against OWASP, PCI DSS, HIPAA, CWE, CAPEC and WASC.

In use

10,000+

organizations work from Deepinfo data, on the platform and through the API. Banks, airlines, telecom operators, defense manufacturers, public institutions and security vendors among them.

Customer stories
Turkish Airlines
Turkcell
Aselsan
Bitsight
Wiley
Albaraka
Invicti
Türksat
Havelsan
Beko
Istanbul Airport
Tüpraş

Start with your own record.

External posture and prioritized findings for one domain, delivered to your work email within 24 hours.

Rather see the platform with our team? Request a demo. Building on the data? Talk to the data team.