Exposed Admin Page Check

Finds admin screens, test servers and developer tools open to the internet. Subdomains come from certificate records, and each host's first page is opened once. No login is attempted.

Related Guides

See what you expose before an attack tool does

Recent breaches started not in core systems but in forgotten internet-facing assets — partner portals, staging servers, admin screens left open. AI-driven attack tools find these at machine speed. DechoNet finds subdomains from Certificate Transparency logs, opens each host once from outside and sorts out admin logins, developer tools, staging, default pages and directory listings. Security teams call this the external attack surface.

How it works

One DNS lookup and one request for the first page (/) per host, following at most three same-site redirects. No logins, no path guessing, no exploits. Anyone sees the counts per category; the per-host detail and the sensitive-file and API-docs path checks open only after the domain owner publishes a DNS TXT record.

FAQ

Can I check someone else’s domain?

You see counts per category and the verdict. Which host exposes what is shown only to a verified owner — that list is an attacker’s target list.

Does the check load our servers or look like an intrusion?

It opens the first page of each host once, like a browser. After verification it also reads five well-known sensitive paths (.env, .git …) and ten standard API documentation paths (/swagger.json, /v3/api-docs, /graphql …) once each — nothing more. No GraphQL query is sent.

It says "admin screen" but we restrict it by IP.

If the restriction works, our servers get "access denied" (403) and the host is not counted as an admin screen. If it was counted, the screen opens from anywhere on the internet.