Use cases
DNS & email security
SPF, DMARC, DNSSEC, and mail routing each live in a different checker, and none of them is crossed with the live infrastructure behind the records. WhisperGraph grades the whole posture in one pass — the includes and where they reach, the mail servers a domain trusts, DNSSEC, DMARC policy — against the reputation of the hosts involved.
And because it watches the DNS layer as a graph, it catches nameserver drift before it becomes a hijack.
Why this is hard without a graph
An email-auth audit that stops at the record misses the point: a perfectly valid SPF include is still a risk if it points at infrastructure you wouldn't trust. Config checkers don't cross into the live graph, so posture and reality drift apart.
What changes with WhisperGraph
The config layer and the infrastructure layer are the same graph. One traversal grades the posture and follows every reference into the hosts it actually trusts, so the audit reflects what's live — not just what's published. The workflows below run it on any domain.
4 workflows in DNS & email security
Each one runs live on the graph — no signup.
Attack-Surface Mapper
See your organisation the way an attacker does. Give it a domain and it maps the full external footprint — every subdomain, the name and mail servers, who registered it, the third-party services it leans on, and the wider web of sites it connects to — and scores the exposure. The starting point for shrinking what's reachable from the outside.
DNS & Email Security Posture
Find out how easily someone could send mail as you. This grades a domain's email posture end to end — its sender authorisation, reporting setup, signing vendors, and mail servers — and flags the gaps that let attackers spoof your brand or that quietly hurt your deliverability. The one-look email-security health check.
Indicator Enrichment
Everything worth knowing about one indicator, on a single card. Give it a domain or an address and it fills in the picture: who registered it, where it's hosted and in which country, its mail and name servers, the network behind it, and a reputation read. The fast way to go from a bare indicator to real context before you decide what to do with it.
Nameserver & DNS Delegation Audit
Your name servers decide where your domain points — and a broken or inconsistent setup is a hijacking opportunity. This audits a domain's delegation, flags stale or mismatched name servers, sizes how much each provider actually handles, and surfaces registry facts — so you can catch delegation weakness before it's exploited.