Lawful public-source and exposure review
OSINT, Dark-Web Exposure and Online Security Posture Assessment
Targeted checks for exposed personal or organisational information, known breach records, impersonation, lookalike domains and internet-facing security issues, with the sources and limits recorded.
Direct access to Alistair Ewing · Free initial consultation · Written estimate before work
Find what is exposed and record what was checked
An online exposure assessment starts with a defined subject and purpose. For an individual, that may mean checking an authorised set of names, usernames, email addresses, telephone numbers or owned domains for public exposure and known breach references. For an organisation, it may include owned domains, subdomains, certificates, public services, websites, mail controls and convincing variants of the brand or domain.
The work combines open-source intelligence with breach and exposure checks across the sources agreed in advance. Relevant results are preserved with their source, URL, date, time and context. Where possible, a finding is corroborated before it is treated as more than an indicator. A historical breach record, a similar domain or an unusual public service can justify action, but none proves current compromise or identifies the person responsible on its own.
This is not covert intrusion, penetration testing or unrestricted monitoring. Personal exposure work is limited to the client’s own information, or another person’s information where a documented lawful purpose and authority pass suitability checks. Searches use public material, approved identifiers and lawfully accessible services. Active validation beyond non-intrusive review of public-facing information requires written authority, a defined target list and a separately agreed method.
Questions the assessment may address
- Which client-approved email addresses, usernames, domains or other identifiers appear in known breach or exposure sources.
- What personal or business information can be found through ordinary search, public records, archived pages, documents, social profiles and other lawful sources.
- Which domains, subdomains, certificates, websites, remote services and mail-security controls are externally visible for assets the organisation owns.
- Whether candidate misspellings, character substitutions or similar domains are registered and whether their observed use may confuse customers or contacts.
- Whether a suspected profile, page, advert, email address or website appears to imitate the subject, brand or payment process.
- Which findings require immediate account-security, registrar, hosting, platform, legal or communications action, and which are lower-confidence leads.
- What can be reduced, corrected, monitored or documented, and what remains outside the client’s control.
Sources and records that may be considered
- Client-approved identifiers and proof of authority for owned accounts, domains and systems.
- Clear-web search results, public profiles, cached or archived pages and exposed documents.
- Authorised breach-intelligence results and lawfully accessible exposure sources.
- DNS and RDAP records, certificate transparency records, website responses and mail-security configuration.
- Publicly visible services and technology indicators for the agreed organisation-owned target list.
- Suspect messages, complete email headers, full URLs and screenshots showing the surrounding page.
- Registrar, registry, hosting, platform and search-provider complaint records and responses.
Two different starting points
An individual review and an organisational review are scoped differently
For individuals and key personnel
An individual online exposure review can map information that a fraudster, impersonator or someone targeting them could find without privileged access. The agreed identifiers may lead to old profiles, reused contact details, exposed documents, breach references, impersonating accounts or links between personal and professional activity.
The purpose is practical risk reduction, not judgement about what someone chose to publish. Results are ranked by likely harm and by what the client can change. Advice may include account-security changes, privacy-setting review, removal requests, preservation of suspected impersonation and referral where a platform, employer, solicitor or law-enforcement report is more appropriate.
For organisations and professional practices
For an organisation, the review considers the public estate that an attacker or fraudster can see. This may include domains and subdomains, certificates, externally visible services, website technology, DNS dependencies, email anti-spoofing controls and forgotten or supplier-managed assets.
Discovery is reconciled with the client’s own asset list. False associations, shared hosting and supplier infrastructure are common, so ownership and confidence are recorded rather than assumed. The output is a prioritised evidence schedule. It is neither a security assurance nor a substitute for penetration testing.
Impersonation and lookalike domains
Preserve first, then choose the right complaint route
- Record the observed material. Preserve the full URL, page, relevant headers, date, time and route by which it was found without entering credentials or interacting unnecessarily.
- Test the relationship. Compare spelling, branding, contact details, certificates, DNS, registration information and observed use. Similarity alone is not proof of malicious intent or common control.
- Identify the services involved. Determine the likely registrar, registry, host, platform, advertising service or search provider and record the confidence and evidence behind that identification.
- Prepare a focused complaint. Assemble the URLs, screenshots, headers, authority and explanation requested by the relevant provider. Formal domain-name disputes may need specialist legal or intellectual-property advice.
- Track the outcome. Record acknowledgements, changes and unresolved points. Removal, suspension, de-indexing and account action are different outcomes and none can be guaranteed.
Useful outputs
What the client receives
Exposure schedule
Source, date, identifier, observed content, confidence, likely significance and the person or team best placed to act on each finding.
External posture map
Agreed domains, services, certificates, mail controls and supplier relationships, with ownership and uncertainty marked.
Impersonation evidence pack
Preserved pages, URLs, headers and infrastructure records organised for provider complaints, legal review or a fraud report.
Prioritised action note
Immediate protective steps, medium-term clean-up, monitoring options, referrals and items that could not be verified.
What the findings cannot prove
- Public and breach sources can be incomplete, false, altered, deleted, recycled or wrongly attributed.
- A breach reference shows that an identifier appeared in a particular source; it does not prove that the account is currently controlled by another person.
- No-result searches do not prove that data, credentials or discussion do not exist elsewhere.
- A registered lookalike domain, similar page or valid certificate does not by itself prove fraud, intent, ownership or a common operator.
- Externally visible software or a reported vulnerability is not proof that the system is exploitable or has been compromised.
- Provider, registrar, registry and platform decisions remain outside Compute Forensics’ control.
- Public availability does not remove privacy, data-protection, contractual or legal obligations.
What is needed for a proportionate estimate
- The person, organisation, brand or matter to be checked and the decision the assessment must inform.
- The exact identifiers and assets authorised for use, including known spelling variants and owned domains.
- Whether the priority is personal exposure, breach records, external security posture, impersonation, a particular site or continuing monitoring.
- Known suspect URLs, profiles or messages described without visiting them again or forwarding harmful content through the website.
- Countries, languages, date range, urgency and any legal, HR, safeguarding or brand-protection context.
- The required output, recipients and whether complaint or takedown coordination is requested.
Please do not attach evidence, passwords or confidential case papers to the public enquiry. A secure route is agreed only after the conflict check.
Official and first-party references
Useful routes before and after an assessment
- NCSC external attack surface management buyer’s guide
- NCSC Check Your Cyber Security for free checks of some externally visible risks affecting UK organisations
- GOV.UK route for reporting suspicious emails and websites
External services have their own eligibility, privacy and reporting terms. These links are provided for context and do not imply endorsement, access to a complete dataset or authority over the outcome.
Frequently asked questions
Can you search the dark web for my email address or company?
Targeted checks can use client-approved identifiers across authorised breach-intelligence services and lawfully accessible sources. The written scope identifies the sources used. Coverage is partial, so the result cannot exclude exposure elsewhere.
Does a breach result mean somebody has my current password?
Not necessarily. It may identify an older incident and data classes associated with it, not the current content of an account. The date, source, password history, reuse and present account controls need separate consideration. Passwords should not be sent through the enquiry form.
Can you review what an attacker can see about our organisation?
Yes, for a written, organisation-owned target list. The work can examine public domains, subdomains, certificates, DNS, email controls, websites and visible services. It is an external exposure assessment, not an assurance that every asset has been found or a penetration test.
Can you find every fake domain similar to ours?
Candidate variants can be generated and checked, but no search can guarantee every registration or future domain. International characters, new registrations, platform accounts and unregistered names create additional limits.
Can you take down a copied or misspelled website?
The service can preserve evidence, identify likely providers, prepare focused complaints and coordinate responses. A registrar, host, registry, platform, search provider or court controls its own decision, so removal and timescale cannot be promised.
Is takedown the same as disavowing a domain in Google?
No. Disavow is an advanced search-engine tool for certain incoming-link problems. It does not close the other domain or remove hosted content. Using it incorrectly can also harm search performance.
Will you monitor the result continuously?
A one-off assessment records the position during the agreed period. A defined repeat-check schedule may be quoted separately, but it is not continuous security monitoring and does not replace internal alerting or the NCSC Early Warning service.
Read all questions about fees, timing, evidence and instructing Alistair
Initial enquiry
Need a clear picture of your online exposure?
Describe the person, organisation or brand, the approved identifiers, the concern and the decision the work must inform. Do not send passwords, stolen material or evidential files. After the initial checks, the proposal will set out the lawful scope, sources, output and itemised estimate.

