Predictable Surveillance Tiers
Zero per-scan overages. Fixed monthly pricing for automated attack surface reconnaissance, dangling DNS takeovers, and email hygiene.
Starter Plan
Essential automated perimeter defense for fast-moving engineering teams.
Pro Plan
High-frequency surveillance and team collaboration for multi-cloud estates.
Detailed Feature Matrix
| Feature / Capability | Starter ($49/mo) | Pro ($129/mo) |
|---|---|---|
| Monitored Apex Domains | 3 Domains | 15 Domains |
| Automated Cadence | Every 24 Hours | Hourly (24x / day) |
| Cloud Takeover Signatures | All 42 Signatures | All 42 Signatures |
| RFC-7208 10-Lookup Barrier Audit | Included | Included (Deep Traversal) |
| TLS Expiry Radar | 30d / 14d / 7d Alerts | 30d / 14d / 7d Alerts |
| On-Demand UI & API Rescans | Unlimited | Unlimited (Priority) |
| Outbox Incident Delivery | Resend DKIM Email | Resend + Slack + Webhooks |
| Engineering Seats | 3 Seats | Unlimited |
Frequently Answered Questions
How does SubdomainWatch detect dangling DNS before an attacker exploits it?
Our engine executes active recursive resolution against 42 documented cloud provider signatures (AWS S3, GitHub Pages, Heroku, Azure, CloudFront, etc.). When a CNAME returns a canonical target that responds with an orphan token (such as NoSuchBucket or 404 Web Site not found), SubdomainWatch flags the finding and dispatches an instant transactional alert before an external actor can claim the resource.
Why is the RFC-7208 10-lookup barrier critical for our business email?
RFC 7208 Section 4.6.4 dictates that evaluating an SPF record must not perform more than 10 DNS queries across all mechanisms (include, a, mx, ptr, exists, redirect). If third-party SaaS services (SendGrid, Zendesk, Google Workspace) push your includes beyond 10 lookups, major mail transfer agents return a PermError, silently routing legitimate corporate email to spam or dropping it entirely.
Does SubdomainWatch require installing an agent or sensor on our servers?
No. SubdomainWatch is 100% external, non-invasive attack surface surveillance. We discover and audit your attack surface from the vantage point of an adversary on the public internet using authoritative DNS resolution, Certificate Transparency (CT) logs, and passive OSINT.
Can our engineering team trigger on-demand scans when pushing DNS changes?
Yes. In the Defense Console, you can trigger instant on-demand scans via the 'Re-scan Now' button, or call our API from your CI/CD pipeline (e.g. Terraform or GitHub Actions) to verify DNS propagation immediately.
What happens when an SSL/TLS certificate is flagged in the radar?
Our TLS Expiry Radar categorizes certificates into 30-day, 14-day, and 7-day alert thresholds. Incidents are automatically queued in the Defense Console and transactional alerts are dispatched via Resend email and Slack so your team can intervene before expiration blackouts affect users.
Can we cancel, upgrade, or change plans at any time?
Yes. All plans are billed on a flexible month-to-month basis with zero lock-in contracts. You can upgrade from Starter to Pro or cancel directly from your console at any time with one click.