Skip to content

Ward opens soon: join the waitlist and we'll email you the day we open.

How to use Ward

Ward looks at your company the way an attacker would from outside, explains what it finds in plain language and keeps watching. This guide explains how it works and what each alert means.

What Ward is

  • Analyzes the external exposure of your company: your domain, email, website and certificates, and the services you have reachable from the internet.
  • Checks who could be impersonating you, and gives you a Ward Score from 0 to 100.
  • Explains each problem and tells you exactly what to do and who should do it.

Ward is passive: it only uses public information and does what any visitor could do. It doesn't install anything, doesn't scan your ports, doesn't try passwords and doesn't change anything in your systems.

Got an email, link or file that looks off? Open Ward AI's Analyzer and Ward tells you whether it looks like fraud. How Ward AI's Analyzer works.

Getting started, once Ward opens

Ward isn't open yet. This is how starting will work; join the waitlist and we'll email you the day we open.

Getting started: add your domain, first scan, review the findings and ongoing monitoring, which alerts you and sends you back to the findings.Add yourdomainFirstscanReview thefindingsOngoingmonitoringWard alerts you when something changes
  1. 1

    Scan your domain for free

    Type your domain on the home page. In about a minute you'll see your Ward Score, how many problems you have by severity and how you could be attacked. No sign-up needed.
  2. 2

    Create your account

    Sign in with your email: we send you a one-time link, there are no passwords. Scanning any domain is free and gives you a trial report. To monitor your domains every day, choose the Essential or Professional plan: you are billed when you subscribe.
  3. 3

    Add your domain

    In Domains, add your domain, or use “Monitor this domain” from a report you've just run so the scan you already did is kept.
  4. 4

    Prove it's yours

    Ward only shows the full detail and turns on monitoring for domains you prove you own. You can do it in two ways (the exact value appears in the domain page):

    • A TXT record in your DNS at _ward.yourdomain.com whose value starts with ward-verificacion=.
    • A meta tag in your home page: <meta name="ward-verificacion" content="…">.
  5. 5

    Let Ward watch

    From then on Ward scans your domain on its own and alerts you by email when something serious appears or gets worse. Choose who gets the alerts in Alerts.
  6. 6

    Fix and confirm

    Open each finding, follow the steps (or send them to whoever manages your website or email) and, once fixed, mark it as “Pending verification”. Ward checks it again and closes it when it's really fixed.

A weekly routine

Once Ward is watching, you only need a little time each week:

  1. 1

    Read the Monday summary

    One email per domain: what needs action and what you should just know. If nothing needs action, you're done.
  2. 2

    Open the Overview

    Look at the change in your Ward Score over 30 days and at “Start with these”: critical and high findings first.
  3. 3

    Move findings forward

    Give each one a status that tells the truth, fix what's due and mark fixed ones as “Pending verification”.
  4. 4

    Check what's coming

    Planned fixes due soon, findings pending verification and expirations in the next 60 days.
Instant alerts don't wait for the week: act on them the day you get them. What to do with each alert.

How often Ward checks

Monitored domains are scanned again automatically. You can also run a scan at any time with “Scan now” on the domain page.

Domain and certificate expiry
every day
Email, reputation, breaches and ransomware
every day
Exposed services, website and subdomains
every 7 days

Newly registered lookalike domains and new certificates for your domain are watched separately, several times a day.

What Ward never does

  • Scan your ports itself: open services are read from specialised public databases.
  • Probe paths, files or subdomains by trial and error.
  • Try passwords or log in anywhere.
  • Visit your home page more than once per scan.
  • Change anything in your systems or fix things for you.
Ward is not a substitute for a security audit or a penetration test. It tells you what anyone can see from the outside, which is where most attacks on small businesses start. What Ward does and doesn't do.