We don't know exactly what you're running. We know exactly what changed since yesterday.
SurfaceDiff scans your domains, subdomains, DNS, ports, TLS certificates and web services on a schedule - and tells you the moment something new appears. Yesterday it wasn't public. Today it is. You get the evidence.
Manage multiple customer domains? Explore the Hosting Pilot. Running managed infrastructure at MSP, MSSP or data centre scale? See the guided assessment for managed cloud providers.
Sensitive public port opened: 203.0.113.4:6379
redis · no auth · absent from yesterday's scan
How it works
We scan what's actually public
Subdomains, DNS records, open ports, TLS certificates, live web services and crawlable endpoints - the same reconnaissance an attacker would run, on a schedule.
Raw results become one snapshot
Every scan is normalized into a single structured snapshot, so this week's result can be compared with last week's - not just skimmed.
We diff it against last time
New hosts, new ports, changed certificates, services that vanished. Exposures you've already reviewed stay quiet - only real change surfaces.
You get the incident, with evidence
A severity, a title, and the exact evidence behind it - timestamped and kept, so "yesterday it wasn't there" is something you can prove.
Built to be trusted with this
Full-surface scanning
DNS, subdomains, open ports, TLS certificates, web services and crawlable endpoints - not just a port scan.
What's running, not just what's open
Open ports get fingerprinted for real service and version evidence, gathered safely without tripping your own security tooling.
Noise you control
Mark a port or service as an exposure once, with a reason, and future scans stay quiet about it - until you say otherwise.
An audit trail, not just a dashboard
Every mute, un-review and re-enable is logged with who did it and why - useful the day someone asks why this was open.
Team roles, not shared logins
Owner, admin, member and viewer roles - scope a client's login to just the domains they own, not your whole account.
Built for shared infrastructure
One change on a shared server becomes one incident, not fifty - and pricing counts a shared host once, not per domain on it.
Go back to any scan
Every scan is kept, not just the latest. Browse any past snapshot, or compare two dates side by side to see exactly what changed - useful the day someone asks what was exposed, not just what's exposed now.
See what's actually exposed.
Add a domain, get a baseline, and know the moment it changes.
Scan your domain free