For MSPs & IT Cybersecurity Consultants
Find businesses with exposed security risks. Pitch the protection with proof.
SMBs rarely think about email spoofing or leaked credentials until an incident happens. SiteAssay inspects client-side code, DNS authentication, and server headers to reveal critical security gaps, giving you undeniable proof to pitch high-ticket MSP retainers.
- 234
- Security, TLS, DNS and email authentication signals evaluated per domain
- 100%
- Passive inspection, using the standard HTTP and DNS requests a browser makes
- 0
- Invasive or exploitative probes. Every check is one a browser could make
- 48
- Specialised adapters, each measuring against a published standard
Four high-margin IT security service angles you can pitch today
Every check maps directly to a billable IT project or recurring security retainer.
Email Authentication & DMARC
Verify SPF syntax, DKIM key presence, DMARC enforcement (p=reject/quarantine), BIMI records, and MX blacklist inclusion to prevent domain spoofing.
Leaked Secrets & API Keys
Scan client-side JavaScript bundles for leaked Stripe, OpenAI, AWS, and database connection strings left by careless developers.
Supabase & BaaS Exposure
Probe unauthenticated Row Level Security (RLS) tables to identify database endpoints leaking customer PII or transaction records.
TLS & Security Headers
Audit SSL certificate expiry, protocol versions, HSTS enforcement, Content-Security-Policy (CSP), and X-Frame-Options clickjacking protection.
Safe, Compliant & Non-Invasive
Objective security diagnostics without intrusive vulnerability scans.
SiteAssay performs strictly passive, publicly accessible measurements. We do not attempt SQL injection, brute-forcing, or port scanning. All measurements reflect only what any browser or search bot reads on public web surfaces, keeping your agency 100% compliant.
Read our security commitment- RFC & NIST Aligned
- All email deliverability and cryptographic checks are anchored directly to published IETF RFCs.
- Executive-level risk scoring
- Translates technical CVEs and DNS record omissions into business risk language (e.g. "Email spoofing risk: High").
- Copy-ready DNS & server fixes
- Includes ready-to-deploy DNS TXT records and Nginx/Apache configuration snippets for your technicians.
What MSPs and security teams inspect with SiteAssay
A comprehensive security health sweep run automatically on every prospect domain.
DMARC & SPF Records
Inspects SPF lookup limits, syntax errors, DMARC reporting mailboxes, and policy enforcement level.
Exposed Source Maps
Identifies production .map files that expose proprietary frontend application source code.
Open Directory Paths
Checks for exposed .git repositories, .env files, and backup archives left in public web roots.
Server Information Leaks
Checks Server and X-Powered-By banners exposing unpatched web server versions and frameworks.
Frequently Asked Questions for MSPs
Are SiteAssay security audits legal to run on prospect websites?
Yes. All checks performed by SiteAssay are strictly passive and non-invasive. We read public DNS records, public HTTP headers, and public JavaScript files that are transmitted to any web browser. We do not perform port scans, penetration tests, or authentication bypasses.
How does this help an MSP sell services?
When pitching an SMB owner, an abstract pitch about "cybersecurity" is rarely effective. Showing them their exact domain has a missing DMARC policy (meaning anyone can send emails pretending to be their CEO) or an exposed API key creates immediate urgency to hire your firm for IT remediation.
Can my technical staff use this via API or CLI?
Yes. On the Agency tier and above, SiteAssay provides a developer REST API, webhooks, and an MCP server, allowing your technicians to trigger audits directly from your ticketing or CRM systems.
Protect local businesses and grow your MSP
Run your first security and email deliverability audit in 60 seconds. Start free with no credit card.