Reconnaissance report
google.com
A populated domain assessment showing the evidence, context, safeguards, and follow-up paths available in Deep Security Recon. Values are a point-in-time public-source snapshot; gated providers are identified instead of simulated.
Complete domain scan profile
Results are grouped as customers see them after a full scan, with unavailable or target-specific checks kept visible.
Domain & DNS 7 / 7
- DNS records
- Registration / RDAP
- WHOIS API
- WHOIS history
- Subdomain discovery
- DomainTools pivot
- DNSDumpster map
Mail security 3 / 3
- MX records
- SPF, DKIM & DMARC
- DNS & mail trust
Web & attack surface 8 / 8
- URLScan.io
- ThreatYeti
- TLS & certificates
- HTTP posture
- CISA KEV
- Surface safeguards
- Company & news
- Personnel search
Network intelligence 4 / 4
- IP geolocation
- Shodan exposure
- IP privacy & abuse
- VirusTotal reputation
Identity & exposure 3 / 6
- Breach history
- Credential exposure
- Account exposure
- Email lookup · N/A
- Username OSINT · N/A
- Phone intelligence · N/A
Vehicle research 0 / 2
- Vehicle data · N/A
- VIN marketplaces · N/A
Not applicable means the module requires a different target type, such as an email address, username, phone number, or VIN. It remains visible here so customers can see the full platform coverage.
How the public services connect
Control coverage
- 9 passed
- 2 review
- 5 informational
Findings by severity
Evidence and recommended action
Browser policy is report-only on the sampled homepage
The observed response supplied Content-Security-Policy-Report-Only. Confirm enforcement is intentional and evaluate an enforced policy where compatible.
Header baseline varies by endpoint
The sampled homepage exposed clickjacking protection but did not return every optional hardening header. Validate host-by-host instead of assuming inheritance.
Mail anti-spoofing policy is enforced
DMARC publishes p=reject; SPF identifies Google mail infrastructure and CAA restricts certificate issuance to pki.goog.
HTTPS and canonical redirect respond
The apex domain returned a permanent redirect to the HTTPS www host, and the destination returned HTTP 200.
Authentication posture
Public endpoint posture
Domain profile
Network context
Reputation correlation
Shodan exposure
Rendered web analysis
Discovered public surface
Public identity context
Public exposure checks
Evidence retained for analyst review
What was observed and what was not asserted
What to do next
- 01Validate the intended CSP rollout
Confirm whether report-only mode is deliberate on the sampled homepage and move mature directives to enforcement when compatible.
- 02Compare headers across public hosts
Check that HSTS, content-type, referrer, permissions, and framing policy are consistently applied where appropriate.
- 03Monitor DNS and certificate changes
Alert on unexpected nameserver, MX, CAA, certificate, and edge-host changes instead of treating this snapshot as permanent.
Demonstration only. This is a non-invasive, point-in-time summary of public responses for google.com collected on 12 September 2026 UTC. It is not affiliated with Google and is not a complete security assessment. DNS, routing, headers, certificates, and provider results can change.
