Passive · public-data only · built for self-hosters
See every subdomain, cert, and lookalike the internet knows about your domain.
Then get alerted the hour it changes. Perimeter watches the edge of your domain from Certificate Transparency, DNS and RDAP — for the solo founder on a Caddy VPS who can't justify enterprise pricing for Censys or Detectify.
No signup. Public sources only — we never scan or probe your servers.
What Perimeter watches
New subdomains
Every hostname that gets a certificate shows up in a public Certificate Transparency log. We diff those logs against your saved baseline and tell you when a new one — the forgotten staging. box — appears.
Lookalike domains
We generate typo, homoglyph and TLD-swap permutations of your domain and check RDAP to see which are registered. A freshly-registered acme-support.com is how the phishing starts.
Expiring certificates
We track the not_after on your certs and warn you at 14 days and again at 3 — so a lapsed cert never takes your app dark.
DNS drift
A changed MX, NS or TXT record can mean a mail or SPF hijack. We baseline your DNS and flag drift.
The one promise
Nothing new should appear on your perimeter without you hearing about it — and every signal we send comes from data that was already public. Here's exactly how it works, and what it will never do.
From report to watcher
The free report is genuinely complete.
Type your domain, see your whole public footprint in seconds, share the link. What you pay for is continuity: the diff against your baseline and an email the moment something changes — like this.
- 1Run the free report — no account needed.
- 2Sign up and verify you own the domain (DNS TXT or an HTTP file).
- 3Subscribe, and Perimeter watches it on a schedule and alerts on change.
Why not the tool you'd reach for today
Enterprise attack-surface tools price out the people most likely to get hit.
Opportunistic scanning and typosquat phishing don't skip you because you're small. But Censys, Detectify and DomainTools are built and priced for security teams — so most self-hosters run nothing.
| Perimeter | Censys / Detectify | DomainTools | |
|---|---|---|---|
| Built for | Solo founders & small dev shops | Enterprise security teams | Brand & fraud teams |
| Entry price | Free report · $19/mo | From ~$249/mo, mostly quote-based | Enterprise quote |
| Exposed subdomains (CT) | Yes — with change alerts | Yes | No |
| Typosquat / lookalike watch | Yes — bundled in | Partial / add-on | Yes — sold separately |
| Passive-only (never scans you) | Yes, by design | No — active scanning | N/A |
| Setup | Type a domain — 10 seconds | Onboarding & config | Sales call |
Competitor pricing reflects publicly reported entry pricing at time of writing (Censys and DomainTools are quote-only); Perimeter isn't affiliated with any of them.
Two plans
Who this is for
You run your own box.
One apex domain, a handful of subdomains — app., api., www., and a couple you'd forgotten. Caddy and systemd on a Hetzner or DigitalOcean VPS, not a managed PaaS. You've read the HN threads about leaked staging databases and lookalike-domain phishing, and you've been meaning to "check crt.sh sometime."
Perimeter is that check, running for you on a schedule — for the price of a couple of coffees a month.
Start with what the internet already knows.
One domain, ten seconds, no signup. See your exposure, then decide if you want it watched.
Run the free report