Deep SecurityDeep Security
PUBLIC-SOURCE DEMONSTRATION · SNAPSHOT 12 SEP 2026

Reconnaissance report

google.com

A populated domain assessment showing the evidence, context, safeguards, and follow-up paths available in Deep Security Recon. Values are a point-in-time public-source snapshot; gated providers are identified instead of simulated.

OBSERVED POSTURE91out of 100LOW RISK
DOMAIN STATUSActiveRegistered 15 Sep 1997
DNS EVIDENCE34+Records sampled
MODULES SHOWN3025 applicable to domain
REVIEW ITEMS2Hardening opportunities
SCAN EXECUTION

Complete domain scan profile

Results are grouped as customers see them after a full scan, with unavailable or target-specific checks kept visible.

Snapshot: 12 Sep 2026 UTC

Domain & DNS 7 / 7

  • DNS records
  • Registration / RDAP
  • WHOIS API
  • WHOIS history
  • Subdomain discovery
  • DomainTools pivot
  • DNSDumpster map

Mail security 3 / 3

  • MX records
  • SPF, DKIM & DMARC
  • DNS & mail trust

Web & attack surface 8 / 8

  • URLScan.io
  • ThreatYeti
  • TLS & certificates
  • HTTP posture
  • CISA KEV
  • Surface safeguards
  • Company & news
  • Personnel search

Network intelligence 4 / 4

  • IP geolocation
  • Shodan exposure
  • IP privacy & abuse
  • VirusTotal reputation

Identity & exposure 3 / 6

  • Breach history
  • Credential exposure
  • Account exposure
  • Email lookup · N/A
  • Username OSINT · N/A
  • Phone intelligence · N/A

Vehicle research 0 / 2

  • Vehicle data · N/A
  • VIN marketplaces · N/A

Not applicable means the module requires a different target type, such as an email address, username, phone number, or VIN. It remains visible here so customers can see the full platform coverage.

DOMAIN & DNS INFRASTRUCTURE

How the public services connect

Live-report format
DOMAINgoogle.comPublic DNS zone
A
172.253.132.100 + 5 moreRotating IPv4 edge endpoints
Web
NS
ns1–ns4.google.comFour authoritative nameservers
DNS
MX
smtp.google.com · priority 10Active mail exchanger
Mail
SECURITY CONTROLS

Control coverage

91%observed
  • 9 passed
  • 2 review
  • 5 informational
RISK DISTRIBUTION

Findings by severity

Critical0
High0
Medium0
Low2
Info5
TECHNICAL FINDINGS

Evidence and recommended action

Observed responses
LOW

Browser policy is report-only on the sampled homepage

The observed response supplied Content-Security-Policy-Report-Only. Confirm enforcement is intentional and evaluate an enforced policy where compatible.

Review
LOW

Header baseline varies by endpoint

The sampled homepage exposed clickjacking protection but did not return every optional hardening header. Validate host-by-host instead of assuming inheritance.

Review
PASS

Mail anti-spoofing policy is enforced

DMARC publishes p=reject; SPF identifies Google mail infrastructure and CAA restricts certificate issuance to pki.goog.

Verified
PASS

HTTPS and canonical redirect respond

The apex domain returned a permanent redirect to the HTTPS www host, and the destination returned HTTP 200.

Verified
EMAIL SECURITY

Authentication posture

SPFPublished
v=spf1 include:_spf.google.com ~all
DMARCReject
v=DMARC1; p=reject; aggregate reporting enabled.
MTA-STS / TLS-RPTPublished
Transport-security policy and reporting records observed.
TLS & WEB

Public endpoint posture

HTTPSHTTP 200
www.google.com returned an encrypted response.
Apex redirectHTTP 301
google.com consolidates traffic onto https://www.google.com/.
ClickjackingProtected
X-Frame-Options: SAMEORIGIN was observed.
REGISTRATION & OWNERSHIP

Domain profile

RDAP + WHOIS
RegistrarMarkMonitor Inc.
Registry handle2138514_DOMAIN_COM-VRSN
Registered15 Sep 1997
Expires14 Sep 2028
Nameserver set4 observed
Registry locks6 protections
IP & ASN INTELLIGENCE

Network context

IPv4 pool6 sampled
172.253.132.100, .101, .102, .113, .138, .139
IPv6 pool4 sampled
2607:f8b0:4023:2c03::/64 responses observed.
Network ownerGoogle LLC
Anycast and regional routing can change the returned edge.
THREAT INTELLIGENCE

Reputation correlation

VirusTotalProvider-gated
Live customer reports show vendor detections when the configured provider returns them.
ThreatYetiContext available
Threat pivots remain separated from direct findings.
CISA KEVTechnology-dependent
Correlation requires confidently observed affected technology.
PORTS & SERVICES

Shodan exposure

80 / TCPHTTPRedirect path
443 / TCPHTTPSReachable
Other portsNot actively probedProvider-gated
URLSCAN.IO

Rendered web analysis

Final URLhttps://www.google.com/
Page status200
Edge servergws
Rendered scanAvailable in full run
SUBDOMAINS & CERTIFICATES

Discovered public surface

CT logs + bounded DNS
RecordObserved valueTTLAssessment
A6 rotating IPv4 answers300sResolved
AAAA4 IPv6 answers300sResolved
CAA0 issue “pki.goog”~6hRestricted
MX10 smtp.google.comDynamicConfigured
COMPANY & PERSONNEL

Public identity context

OrganizationGoogle LLC
Brand and infrastructure attribution from public records.
RegistrarMarkMonitor Inc.
Registry-confirmed registrar relationship.
Personnel searchExternal pivot
Public professional-profile results remain references, not identity claims.
BREACH & CREDENTIAL EXPOSURE

Public exposure checks

Breach catalogProvider-dependent
No breach result is fabricated for this public demonstration.
Credential searchAuthorization required
Exact exposure results require verified domain ownership.
Privacy safeguardsEnforced
Sensitive credential values are not displayed in the demo.
RAW DNS INVENTORY

Evidence retained for analyst review

Google Public DNS
TypeValueCountUse
NSns1.google.com through ns4.google.com4Authoritative DNS
TXTSPF plus ownership and service verifications17 sampledPolicy & validation
SOAns1.google.com · dns-admin.google.com1Zone authority
HTTPSALPN h2,h3 advertised1Modern transport
EVIDENCE & CONFIDENCE

What was observed and what was not asserted

Transparent methodology
DNS sourceGoogle Public DNS
Registration sourceVerisign RDAP
HTTP sourceDirect public response
Active port scanNot performed
Credential exposureAuthorization gated
Provider-only findingsNot simulated
PRIORITIZED ACTION PLAN

What to do next

  1. 01
    Validate the intended CSP rollout

    Confirm whether report-only mode is deliberate on the sampled homepage and move mature directives to enforcement when compatible.

  2. 02
    Compare headers across public hosts

    Check that HSTS, content-type, referrer, permissions, and framing policy are consistently applied where appropriate.

  3. 03
    Monitor DNS and certificate changes

    Alert on unexpected nameserver, MX, CAA, certificate, and edge-host changes instead of treating this snapshot as permanent.

Demonstration only. This is a non-invasive, point-in-time summary of public responses for google.com collected on 12 September 2026 UTC. It is not affiliated with Google and is not a complete security assessment. DNS, routing, headers, certificates, and provider results can change.