External exposure scanning · Resources Center · current as of June 2026
HRS Exposure shows you what an attacker sees when they look at your organization from the outside — your people, your brand, and your domains — before that information is used against you. It looks only at what is already discoverable on the public internet, so there's nothing to install and no access to grant. In a couple of minutes you get a graded picture of your external exposure and a clear, prioritized list of what to fix. This guide explains how to run a scan, read your results, and turn them into action.
Contents
- What HRS Exposure is
- How a scan works
- Running a free scan
- Your exposure snapshot
- Getting the full report
- Reading your grade
- The five exposure categories
- Findings and severity
- From a one-time scan to continuous monitoring
- Using the console
- How exposure connects to your Human Risk Score
- Privacy and how it works
- FAQ
- Glossary
1. What HRS Exposure is
Most security tooling looks inward — at the endpoints, mailboxes, and networks you control. HRS Exposure looks the other way: it takes the attacker's outside-in view of your organization and tells you what they'd find before they ever send a phishing email.
It answers questions an attacker asks first:
- Whose credentials have already leaked, and are any sitting in active infostealer logs?
- Which executives and high-value staff are easy to research and impersonate?
- Can someone send email that looks like it came from your domain?
- Are there look-alike domains registered to imitate you?
- Is your public web and TLS posture exposing you?
Because it works entirely from publicly discoverable sources, there is no agent to deploy, no mailbox to connect, and no scan of your internal systems. You point it at a domain; it reports what the outside world can already see.
The output is a single exposure grade (A–F) with a supporting posture score, broken down into five categories, each with specific, evidence-backed findings you can act on.
2. How a scan works
When you run a scan on a domain, HRS Exposure runs five independent checks ("modules") in parallel and then combines their results:
- Discover — it identifies your domain's public footprint: mail configuration, web presence, related and look-alike domains.
- Check — each module gathers evidence from public sources and threat intelligence (leaked-credential corpora, infostealer logs, domain registration data, email-authentication records, web/TLS configuration).
- Grade — a deterministic scoring engine turns the evidence into a grade for each category and an overall composite, along with a list of findings ranked by severity.
- Report — results appear as a snapshot immediately and as a full report you can keep.
A scan typically completes in well under a minute. Nothing about the scan touches your internal systems or requires you to change anything first.
3. Running a free scan
Anyone can run a free scan from the HRS Exposure landing page — no account required.
- Enter your domain (for example,
yourcompany.com). You can also paste a work email; HRS Exposure will use its domain. - Complete the brief anti-abuse check.
- The scan runs and your snapshot appears.
The free scan is rate-limited per network to prevent abuse, and it covers the live, domain-level categories. The deeper, person-level detail (which executives and which employees are exposed) is reserved for the full report and for monitored, domain-verified organizations — see section 9.
4. Your exposure snapshot
The snapshot is the at-a-glance result of a free scan. It's designed to tell you how exposed you are without exposing the details to anyone who happens to run a scan on your domain. It has three parts:
The exposure score. A gauge showing your overall grade letter (A–F), your posture score (0–100), and a plain-language risk band — low, moderate, or high exposure.
The risk summary. Counts of findings by severity — how many critical, high, medium, and low issues the scan surfaced — so you immediately know the shape of the problem.
Category status. A line for each of the five categories showing whether it's clear or has findings. The live categories (email, brand, and web posture) show their status directly; the person-level categories (executive and credential exposure) are summarized but their specifics are held back for the full report.
The snapshot deliberately shows you that you have exposure and how much — it does not print the exploitable specifics on a public page. To see the evidence behind each finding, request the full report.
5. Getting the full report
From the snapshot, choose Email me the full report and enter your work email. HRS Exposure sends you a private link to your complete report.
A few things worth knowing:
- The link is private and time-limited. It's unique to you, can't be guessed from your scan, and expires after a set window. Treat it like any other sensitive link.
- The full report adds the evidence behind every finding: the specific authentication failures, the look-alike domains, the categories of leaked credentials, and the executive-exposure detail — everything the snapshot summarized.
- It arrives in seconds. If it doesn't, check spam; the sender is your HRS Exposure mail domain.
The full report is the artifact you share internally to drive remediation and the baseline you measure improvement against on your next scan.
6. Reading your grade
HRS Exposure expresses exposure as a letter grade and a posture score.
| Grade | Posture score | What it means |
|---|---|---|
| A | ~90–100 | Low exposure. Strong external posture; few or no actionable findings. |
| B | ~80–89 | Low–moderate exposure. Generally healthy with a few items to tidy up. |
| C | ~65–79 | Moderate exposure. Real gaps an attacker could use; worth prioritizing. |
| D | ~50–64 | Elevated exposure. Multiple meaningful weaknesses. |
| F | below ~50 | High exposure. Serious, exploitable issues that need prompt attention. |
The posture score runs 0–100, where higher is better — it measures how strong your posture is, not how much risk you carry. An A with a 95 means the outside world finds very little to work with; an F means an attacker has a lot to work with.
Two important points about how grading works:
- You get a grade per category and one composite grade. A strong overall grade can still hide a single weak category, so always read the category breakdown, not just the headline.
- A clean check never improves your grade on its own. The absence of a signal doesn't "absolve" you — for example, finding no leaked credentials adds no risk weight, but it isn't treated as proof of safety. Grading only adds weight for evidence of exposure; it never credits the lack of evidence.
7. The five exposure categories
Every scan covers the same five categories. Each one maps to a way attackers actually get in.
Credential exposure
What it checks. Leaked credentials and active infostealer infections associated with your domain, drawn from breach corpora and stealer-log intelligence. It surfaces how many accounts on your domain appear in known breaches and, critically, whether any are tied to active infostealer logs — which often include live session data, not just old passwords.
Why it matters. Reused and stolen credentials are the most common way attackers get an initial foothold. An infostealer hit is more urgent than an old breach because it can mean an attacker has a working session right now.
What you'll see. Counts of exposed accounts and breach categories, with severity raised for infostealer activity. HRS Exposure records only the presence of an exposure — it never stores passwords. With a verified domain and a synced roster, the report can show which employees are affected (see section 9).
What to do. Force resets for affected accounts, prioritize anyone with infostealer activity, and turn on phishing-resistant MFA.
Executive exposure
What it checks. The heightened exposure of your high-value people — executives, finance, and IT admins — whose public professional footprint and breach history make them prime targets for business email compromise (BEC) and impersonation.
Why it matters. Attackers research leadership before they strike. The easier an executive is to profile and the more their details have leaked, the easier they are to impersonate or target.
What you'll see. An assessment of which high-value roles are most exposed and why, in the full report.
What to do. Tighten executive impersonation controls (DMARC enforcement, display-name protection), brief high-value staff, and consider executive-specific monitoring.
Email spoofing (SPF / DKIM / DMARC)
What it checks. Whether your domain's email authentication actually stops someone from sending mail that looks like it came from you. It evaluates your SPF, DKIM, and DMARC records and policy.
Why it matters. Weak or missing email authentication is what lets attackers spoof your domain to phish your staff, customers, and partners. A DMARC policy of p=none, for instance, monitors but doesn't block spoofing.
What you'll see. A plain reading of each mechanism and the specific weaknesses — missing records, soft-fail SPF, or an unenforced DMARC policy.
What to do. Move DMARC toward enforcement (p=quarantine then p=reject), tighten SPF, and ensure DKIM is signing.
Look-alike domains
What it checks. Registered domains that resemble yours — typosquats and "cousin" domains — that could be used to impersonate you in phishing or fraud.
Why it matters. A convincing look-alike domain is the staging ground for credential-harvesting pages and invoice fraud. Knowing they exist lets you get ahead of them.
What you'll see. The look-alike domains discovered, so you can assess and act on the ones that matter.
What to do. Monitor the riskiest look-alikes, consider defensive registration of the most dangerous variants, and prepare takedown paths.
Web & TLS
What it checks. The security posture of your public web presence and TLS configuration.
Why it matters. A weak public web/TLS posture is both a direct risk and a credibility signal — it's part of the attack surface attackers probe first.
What you'll see. The specific web and TLS weaknesses found.
What to do. Address the flagged configuration issues with whoever runs your web infrastructure.
8. Findings and severity
Within each category, HRS Exposure emits findings — specific, evidence-backed observations. Every finding carries a severity:
| Severity | Read it as |
|---|---|
| Critical | Act now. Directly exploitable or already being exploited (e.g., active infostealer sessions). |
| High | Address soon. A clear, usable weakness. |
| Medium | Plan to fix. Meaningful but not immediately dangerous. |
| Low | Tidy up. Minor hygiene. |
A good way to work a report: start at the top of the severity list, fix the criticals and highs first, and re-scan to confirm they've cleared and your grade has improved. Because each finding states why it was raised and the evidence behind it, you can hand individual findings to the right owner without re-explaining the context.
9. From a one-time scan to continuous monitoring
A free scan is a point-in-time snapshot. Your exposure changes constantly — new credentials leak, new look-alike domains get registered, DNS records drift. Monitored organizations get the continuous version:
- Scheduled re-scans. Each monitored domain is automatically re-scanned on a cadence you choose (for example, weekly), so new exposure is caught as it appears rather than the next time someone remembers to check.
- Change over time. Because monitoring keeps a history, you can see whether your posture is improving and when something new shows up.
- Per-employee detail. Once you verify ownership of a domain (by adding a DNS record HRS Exposure provides) and sync your roster, the credential and executive categories can show which specific people are affected — not just totals. This person-level detail is gated behind domain verification by design, so one organization can never see another's people.
Monitoring and per-employee detail are managed in the console by your administrator — see the Administrator Guide for setup.
10. Using the console
If your organization runs HRS Exposure as a monitored service, signed-in users get a console. What you can see and do depends on your role (your administrator assigns it):
- Viewer — read access. Review scans, findings, and reports.
- Analyst — everything a viewer can do, plus run on-demand scans and manage which domains are monitored.
- Admin — everything, plus manage users, organization settings, analytics, and the audit log.
The main areas:
Console (dashboard). Your at-a-glance posture: latest grade, number of monitored domains, your count of critical and high findings, exposed-account totals, and a list of recent scans.
Scan detail. Click any recent scan to open its full result — the composite grade and a breakdown by category, with every finding's severity, title, explanation, and count. Complete scans offer a downloadable report.
Domains. The list of domains under continuous monitoring, each with its status, re-scan cadence, next scheduled scan, and latest grade. Analysts and admins can add a domain, pause or resume it, remove it, or trigger an immediate re-scan.
Profile. Your account and password.
Everything you see is scoped to your own organization. You only ever see your organization's scans, domains, and findings.
11. How exposure connects to your Human Risk Score
HRS Exposure isn't a standalone scanner bolted onto the side — it's the external-signal source for the wider HumanRisk Shield platform.
When you run Exposure as part of HRS, external findings feed your people's Human Risk Score. A person whose credentials show up in an active infostealer log, or an executive who's highly exposed, carries more real-world risk — and Exposure's findings let that risk be reflected where it drives action: targeted training, tighter controls, and reinforcement aimed at the people who actually need it. In other words, what attackers can see about your people becomes a signal that helps protect them.
This connection is what separates "a list of exposures" from a closed loop: discover the external exposure, attribute it to real people, and reduce it through the rest of the platform.
12. Privacy and how it works
A few principles worth being explicit about, because they shape what HRS Exposure is and isn't:
- Outside-in only. Exposure assesses what's already discoverable on the public internet. It does not access your internal systems, your mailboxes, or your endpoints.
- No passwords, ever. For credential exposure, HRS Exposure records only the presence of an exposure — that an account appears in a breach or stealer log — never the password itself.
- Honest about gaps. If a check couldn't run (for example, an intelligence source wasn't reached), the report says so plainly rather than implying everything is clean. A "not checked" result is never presented as a pass.
- Person-level detail is gated. The specifics of which employees are exposed are only available to organizations that have verified ownership of the domain. A public scan never reveals another organization's people.
13. FAQ
Do I need to install anything or give access to my systems? No. HRS Exposure works entirely from public sources. You point it at a domain.
Is the free scan really free, and is it limited? Yes, it's free. It covers the domain-level categories and is rate-limited per network to prevent abuse. Person-level detail requires the full report and, for the deepest detail, a verified domain.
Why does the snapshot hide some details until I get the report? So that running a scan on a domain doesn't hand exploitable specifics to just anyone. The snapshot shows your grade and the shape of your exposure; the full report — sent to your email — contains the evidence.
What does the grade actually measure? Posture. The score runs 0–100 where higher is better; the letter A–F summarizes it. Higher posture means less for an attacker to work with.
My grade is an A — am I safe? An A means low external exposure from what's publicly discoverable. It's a strong signal, not a guarantee, and it doesn't speak to your internal controls. Always read the category breakdown.
How often should I scan? Exposure changes continuously. A one-off scan is a useful baseline; continuous monitoring (re-scanning on a cadence) is how you actually stay ahead of new exposure.
Can I see which of my employees are affected? Yes — once your organization verifies ownership of the domain and syncs its roster. This is gated by design so no one can see another organization's people.
An attachment or check shows "not checked." What does that mean? A source couldn't be consulted for that item, so HRS Exposure says so honestly instead of implying it's clean.
14. Glossary
- Scan — one assessment of one domain across the five categories.
- Snapshot — the immediate, summary result of a scan; grade, risk summary, and category status, without the exploitable specifics.
- Full report — the complete result with the evidence behind every finding, delivered by private link to your email.
- Grade — your exposure level expressed A (best) to F (worst).
- Posture score — the 0–100 number behind the grade; higher is better.
- Finding — a specific, evidence-backed observation, with a severity.
- Severity — how urgent a finding is: critical, high, medium, or low.
- Category / module — one of the five areas a scan covers: credential, executive, email spoofing, look-alike domains, web & TLS.
- Monitored domain — a domain re-scanned automatically on a cadence.
- Domain verification — proving you control a domain (via a DNS record) to unlock per-employee detail.
- Infostealer — malware that steals credentials and live session data; an infostealer hit is treated as more urgent than an old breach.
- Human Risk Score — the HumanRisk Shield score that external exposure findings feed into, tying exposure to the specific people who carry the risk.
For setting up monitored domains, users, multi-tenant (MSP) portfolios, and reporting, see the HRS Exposure Administrator Guide. For onboarding support, contact your HRS administrator or the HRS team.