Knowledge base · external security

What does an external security scan check?

An external security scan views your organisation as an outsider can see it from the internet. It maps reachable systems and notable configurations, validates relevant signals and turns them into concrete remediation actions.

Updated: 4 September 2026

The public attack surface

The review starts with the agreed domains and public IP addresses. DNS records, subdomains, certificates and reachable services are inventoried to create a current picture of what is actually connected to the internet, including systems that may have fallen outside normal asset administration.

A visible system is not automatically vulnerable. It should nevertheless have a conscious owner, business purpose and suitable protection. Unused test environments, old VPN endpoints and forgotten admin panels can therefore matter more than a generic vulnerability score suggests.

Ports, services and management interfaces

The scan identifies reachable TCP services and, within the authorisation, attempts to determine the application behind them. Remote access, VPN, RDP, mail, web servers, databases and management interfaces receive particular attention. Version or protocol information is used only where it can be obtained safely and non-destructively.

Context follows discovery: should the service be public, is access restricted, is a secure protocol used and does the visible configuration match its purpose? An open HTTPS port for a public website is normal; an unrestricted server management portal requires a different assessment.

Web, TLS, DNS and email

Website checks include HTTPS, certificates, security headers and notable technical characteristics. DNS may reveal unused references, unintended subdomains or weak email configuration. Email checks can cover MX, SPF, DKIM and DMARC and how those controls work together.

An external scan is not a full web application code audit or an internal Microsoft 365 audit. Those activities need different access, scope and test methods. A sound report states clearly what was and was not assessed.

From signal to useful finding

Automated scanners readily produce long lists. A useful assessment first checks whether a signal is accurate, records evidence and explains the business impact. It then assigns a priority and practical remediation action so administrators know which system needs attention and why.

JotaSec works non-destructively within a written scope. Passwords are not guessed and systems are not penetrated. The External Exposure Scan includes one retest to confirm agreed improvements.

Technical sources

Would you like to know what your organisation exposes?

Have one domain and up to three public IP addresses reviewed manually and in context.