How much of your attack surface
can attackers see?
Sentinel scans your DNS, web headers, TLS configuration, and Microsoft 365 setup — continuously, from the attacker's perspective.
Attackers don't need your password.
They need your misconfiguration.
Sentinel maps three attack surface layers. Each check runs from the public internet — exactly how an attacker would look at your infrastructure.
DNS & Email
Email spoofing starts with one missing record.
DMARC, SPF, and DKIM are public. Attackers check them before you do. A policy set to p=none means anyone can send from your domain.
Web & TLS
Your website answers questions you didn't mean to answer.
Missing security headers tell attackers what protections are absent. An expired or misconfigured certificate tells customers to leave.
Cloud & SaaS
Microsoft 365 ships with defaults that benefit attackers.
DKIM signing is off for custom domains. Legacy authentication stays enabled. MFA isn't enforced. These aren't edge cases — they're defaults.
Add your domain
Enter yourcompany.com. No DNS changes required. No installation. No agents to deploy on your servers. Sentinel reads your public DNS records — that's it.
We scan continuously
SPF, DKIM, DMARC, SSL certificates, MX records, MTA-STS, and Microsoft 365 configuration — checked every 6 hours from multiple locations. Results stored with full history.
Get alerted before problems become incidents
Email, Slack, webhook, or Microsoft Teams when anything changes or degrades. SSL expiry warnings at 30 days and 7 days. DMARC failures within the hour they happen.
Go deeper on
what matters most.
Each attack surface has its own checks.
Start with the one most relevant to you.
For IT teams who manage their own domain and want to know if email spoofing is possible — and whether Microsoft 365 is correctly configured.
For teams who run a public website and want to know what security headers are missing and when their certificate expires.
For M365 tenants who want a baseline check of their security configuration — Conditional Access, MFA gaps, DKIM, and Secure Score.
Simple pricing.
No hidden fees.
All plans include EU data residency. Prices in EUR, billed monthly. Annual billing saves 20%.
Free
No credit card required
Pro
Cancel any time
Team
Cancel any time
Need more? Custom plans for larger teams, MSSP resellers, and enterprise procurement with SLA and Italian-language support.
Contact us →Common questions.
No. Sentinel reads your public DNS records over HTTPS. No DNS changes, no server access, no agents, no code to deploy. You add a domain name and we handle the rest.
We check whether DKIM signing is enabled for your custom domain (not just the onmicrosoft.com default), whether your Conditional Access policies have country-based restrictions, MFA configuration gaps, and your outbound sending limit usage. We surface the gaps that M365's own dashboard buries in menus most admins never visit.
MXToolbox is a manual, point-in-time checker. You run it when you remember to. Sentinel is continuous monitoring — we run the equivalent of MXToolbox every 6 hours, store the history, alert you the moment anything changes, and generate a compliance report from the results. MXToolbox tells you what's wrong today. Sentinel tells you the moment something goes wrong.
Yes. All data is stored in Frankfurt, Germany (AWS eu-central-1). We are an Italian company operating under EU law with GDPR-compliant data processing. Data processing agreements are available in English and Italian.
The report maps each of your findings to the relevant NIS2 Article 21 sub-clause, shows which controls are passing and which are failing, includes the specific remediation steps for each failure, and generates a dated PDF you can share with customers, auditors, or the Italian ACN. It is an automated technical controls assessment — not a legal certification, which we state clearly in the report.
Yes. The free tier covers 3 domains. Pro and Team cover unlimited domains. All domains are monitored on the same schedule and shown in a unified dashboard. You can add subdomains separately — for example monitoring yourcompany.it, mail.yourcompany.it, and news.yourcompany.it as three separate entries.
You receive an alert via your configured channel (email, Slack, webhook, or Microsoft Teams) with the specific finding, its severity, and the exact remediation step to fix it. We don't send you a vague "something is wrong" message — we tell you which check failed, why it matters, and what to change in your DNS or M365 configuration.
Still have questions? hello@groundcontrol.land
Find out if your domain
is vulnerable.
It takes 60 seconds.
No credit card. No installation. No DNS changes. Enter your domain and see your results immediately.