Skip to content

For MSPs & IT Cybersecurity Consultants

Find businesses with exposed security risks. Pitch the protection with proof.

SMBs rarely think about email spoofing or leaked credentials until an incident happens. SiteAssay inspects client-side code, DNS authentication, and server headers to reveal critical security gaps, giving you undeniable proof to pitch high-ticket MSP retainers.

234
Security, TLS, DNS and email authentication signals evaluated per domain
100%
Passive inspection, using the standard HTTP and DNS requests a browser makes
0
Invasive or exploitative probes. Every check is one a browser could make
48
Specialised adapters, each measuring against a published standard

Four high-margin IT security service angles you can pitch today

Every check maps directly to a billable IT project or recurring security retainer.

Email Authentication & DMARC

Verify SPF syntax, DKIM key presence, DMARC enforcement (p=reject/quarantine), BIMI records, and MX blacklist inclusion to prevent domain spoofing.

Leaked Secrets & API Keys

Scan client-side JavaScript bundles for leaked Stripe, OpenAI, AWS, and database connection strings left by careless developers.

Supabase & BaaS Exposure

Probe unauthenticated Row Level Security (RLS) tables to identify database endpoints leaking customer PII or transaction records.

TLS & Security Headers

Audit SSL certificate expiry, protocol versions, HSTS enforcement, Content-Security-Policy (CSP), and X-Frame-Options clickjacking protection.

Safe, Compliant & Non-Invasive

Objective security diagnostics without intrusive vulnerability scans.

SiteAssay performs strictly passive, publicly accessible measurements. We do not attempt SQL injection, brute-forcing, or port scanning. All measurements reflect only what any browser or search bot reads on public web surfaces, keeping your agency 100% compliant.

Read our security commitment
RFC & NIST Aligned
All email deliverability and cryptographic checks are anchored directly to published IETF RFCs.
Executive-level risk scoring
Translates technical CVEs and DNS record omissions into business risk language (e.g. "Email spoofing risk: High").
Copy-ready DNS & server fixes
Includes ready-to-deploy DNS TXT records and Nginx/Apache configuration snippets for your technicians.

What MSPs and security teams inspect with SiteAssay

A comprehensive security health sweep run automatically on every prospect domain.

DMARC & SPF Records

Inspects SPF lookup limits, syntax errors, DMARC reporting mailboxes, and policy enforcement level.

Exposed Source Maps

Identifies production .map files that expose proprietary frontend application source code.

Open Directory Paths

Checks for exposed .git repositories, .env files, and backup archives left in public web roots.

Server Information Leaks

Checks Server and X-Powered-By banners exposing unpatched web server versions and frameworks.

Frequently Asked Questions for MSPs

Are SiteAssay security audits legal to run on prospect websites?

Yes. All checks performed by SiteAssay are strictly passive and non-invasive. We read public DNS records, public HTTP headers, and public JavaScript files that are transmitted to any web browser. We do not perform port scans, penetration tests, or authentication bypasses.

How does this help an MSP sell services?

When pitching an SMB owner, an abstract pitch about "cybersecurity" is rarely effective. Showing them their exact domain has a missing DMARC policy (meaning anyone can send emails pretending to be their CEO) or an exposed API key creates immediate urgency to hire your firm for IT remediation.

Can my technical staff use this via API or CLI?

Yes. On the Agency tier and above, SiteAssay provides a developer REST API, webhooks, and an MCP server, allowing your technicians to trigger audits directly from your ticketing or CRM systems.

Protect local businesses and grow your MSP

Run your first security and email deliverability audit in 60 seconds. Start free with no credit card.