OSINT · Identity · Cloud Recon

TenantRecon

Given any domain, email, or tenant GUID — map the full externally-visible cloud and SaaS attack surface. Surfaces Microsoft 365 tenant identity, the initial onmicrosoft.com domain (recovered via DKIM), federation type, Intune MDM, Teams SIP, a graded email-security posture (SPF · DKIM · DMARC · MTA-STS · BIMI · DNSSEC), Google Workspace presence, and verification tokens from 35+ SaaS platforms. No API keys. No CLI tools.

Tenant ID / GUID onmicrosoft.com recovery Managed / Federated GCC / GCC-High / DoD Intune MDM Teams SIP Email Security Grade SPF · DKIM · DMARC MTA-STS · BIMI · DNSSEC 35+ SaaS Signals Export MD · CSV · JSON

What TenantRecon maps

Tenant Identity

Resolve any domain or email to its Azure AD tenant GUID — the permanent identifier behind every Microsoft 365 organisation. Detects commercial, GCC, GCC-High, DoD, and Azure China environments, plus the tenant region scope.

onmicrosoft.com Recovery

When a tenant signs mail with DKIM, its selector1._domainkey CNAME points into <initial>.onmicrosoft.com. TenantRecon parses that public record to recover the tenant's default initial domain — even after Microsoft retired enumeration (MC1081538).

Federation & Endpoint

Determine whether the tenant authenticates via Azure AD (Managed) or a third-party IdP (Federated) — surfacing protocol, metadata URL, and active auth endpoint — and whether Intune MDM enrollment and device registration are configured.

M365 & Teams Signals

Confirm Exchange Online MX routing, Teams SIP federation SRV, lyncdiscover and Autodiscover CNAMEs, and any third-party mail security gateway (Proofpoint, Mimecast, Barracuda, Cisco) sitting in front of the tenant.

Graded Email Security

An A+–F posture grade computed from SPF (with include-chain analysis), DKIM selectors, DMARC policy, MTA-STS, TLS-RPT, BIMI, and DNSSEC — with prioritised recommendations that surface exactly where spoofing and impersonation defences fall short.

SaaS Footprint Discovery

Detect Google Workspace, Atlassian, Zoom, Slack, Okta, Salesforce, Dropbox, Webex, Twilio, Mimecast, Proofpoint, and 35+ other platforms from DNS TXT verification tokens and SPF includes — then export the whole map as Markdown, CSV, or JSON.

Common use cases

Red Team Pre-Engagement

Map authentication pathways, the initial onmicrosoft.com domain, cloud environment, and SaaS stack before a phishing simulation or M365 attack path assessment.

M&A Due Diligence

Quickly profile a target organisation's cloud footprint and grade its email-security posture before deeper technical assessment.

Phishing Investigation

Determine whether a suspicious domain is tied to a real M365 tenant, identify its cloud environment, and check its email authentication hygiene at a glance.

M365 Onboarding / Audit

Validate tenant configuration, confirm Intune enrollment DNS, and check that SPF, DKIM, DMARC, MTA-STS, and DNSSEC are in place before a new domain goes live.

Third-Party Risk Review

Assess a supplier's cloud posture, email-security grade, and SaaS stack as part of vendor onboarding or periodic review — and attach the CSV/Markdown export to the file.

Blue Team Baselining

Verify what external recon reveals about your own organisation — confirm only expected signals are present, the onmicrosoft.com name isn't over-exposed, and your email grade is where it should be.

Responsible Use: TenantRecon queries only public, unauthenticated Microsoft endpoints and standard DNS records. All data returned is publicly accessible to any internet user. It is designed for legitimate security research, penetration testing with authorisation, red team reconnaissance, M&A diligence, and third-party risk assessments. Do not use this tool to facilitate unauthorised access to any Microsoft tenant or cloud service. Lookups are rate-limited and logged anonymously for abuse prevention.

Frequently asked questions

What does TenantRecon reveal about a Microsoft 365 tenant?

From just a domain, TenantRecon maps the externally-visible footprint of an organization's Microsoft 365 / Azure AD tenant: tenant ID, initial onmicrosoft.com domain (when DKIM is enabled), namespace and federation type, Intune MDM enrollment, Teams SIP, Exchange Online presence, a graded email-security posture (SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI, DNSSEC), Google Workspace usage, and 35+ other SaaS signals — all from public, unauthenticated endpoints.

Can TenantRecon still find the onmicrosoft.com tenant name after Microsoft retired enumeration?

Often, yes. Microsoft retired unauthenticated multi-domain enumeration in 2025 (MC1081538), so sibling domains can no longer be listed. But when a tenant has DKIM enabled, its selector1._domainkey CNAME points into .onmicrosoft.com — TenantRecon parses that public DNS record to recover the tenant's default initial domain without any authentication.

How is the email-security grade calculated?

It is a heuristic 0–100 score derived only from public DNS: SPF (and its all mechanism), DMARC policy/pct/sp, whether DKIM selectors are published, MTA-STS, TLS-RPT, BIMI, and DNSSEC signing. It maps to an A+–F grade with specific recommendations. It is a fast posture indicator, not a substitute for a full email-authentication audit.

Is TenantRecon legal to use?

TenantRecon only queries publicly exposed, unauthenticated endpoints and standard DNS records that any client uses during normal sign-in and mail discovery — no credentials, exploitation, or unauthorized access. It is intended for defenders, red teamers, and researchers assessing their own or authorized targets.

Does it require an account or API key?

No. TenantRecon is free, runs in the browser, and needs no sign-up or API key. Results can be exported as Markdown, CSV, or JSON.