OSINT · Identity · Cloud Recon
Given any domain, email, or tenant GUID — map the full externally-visible cloud and SaaS attack surface. Surfaces Microsoft 365 tenant identity, the initial onmicrosoft.com domain (recovered via DKIM), federation type, Intune MDM, Teams SIP, a graded email-security posture (SPF · DKIM · DMARC · MTA-STS · BIMI · DNSSEC), Google Workspace presence, and verification tokens from 35+ SaaS platforms. No API keys. No CLI tools.
Enter a domain, email, or tenant ID
Resolve any domain or email to its Azure AD tenant GUID — the permanent identifier behind every Microsoft 365 organisation. Detects commercial, GCC, GCC-High, DoD, and Azure China environments, plus the tenant region scope.
When a tenant signs mail with DKIM, its selector1._domainkey CNAME points into <initial>.onmicrosoft.com. TenantRecon parses that public record to recover the tenant's default initial domain — even after Microsoft retired enumeration (MC1081538).
Determine whether the tenant authenticates via Azure AD (Managed) or a third-party IdP (Federated) — surfacing protocol, metadata URL, and active auth endpoint — and whether Intune MDM enrollment and device registration are configured.
Confirm Exchange Online MX routing, Teams SIP federation SRV, lyncdiscover and Autodiscover CNAMEs, and any third-party mail security gateway (Proofpoint, Mimecast, Barracuda, Cisco) sitting in front of the tenant.
An A+–F posture grade computed from SPF (with include-chain analysis), DKIM selectors, DMARC policy, MTA-STS, TLS-RPT, BIMI, and DNSSEC — with prioritised recommendations that surface exactly where spoofing and impersonation defences fall short.
Detect Google Workspace, Atlassian, Zoom, Slack, Okta, Salesforce, Dropbox, Webex, Twilio, Mimecast, Proofpoint, and 35+ other platforms from DNS TXT verification tokens and SPF includes — then export the whole map as Markdown, CSV, or JSON.
Red Team Pre-Engagement
Map authentication pathways, the initial onmicrosoft.com domain, cloud environment, and SaaS stack before a phishing simulation or M365 attack path assessment.
M&A Due Diligence
Quickly profile a target organisation's cloud footprint and grade its email-security posture before deeper technical assessment.
Phishing Investigation
Determine whether a suspicious domain is tied to a real M365 tenant, identify its cloud environment, and check its email authentication hygiene at a glance.
M365 Onboarding / Audit
Validate tenant configuration, confirm Intune enrollment DNS, and check that SPF, DKIM, DMARC, MTA-STS, and DNSSEC are in place before a new domain goes live.
Third-Party Risk Review
Assess a supplier's cloud posture, email-security grade, and SaaS stack as part of vendor onboarding or periodic review — and attach the CSV/Markdown export to the file.
Blue Team Baselining
Verify what external recon reveals about your own organisation — confirm only expected signals are present, the onmicrosoft.com name isn't over-exposed, and your email grade is where it should be.
Responsible Use: TenantRecon queries only public, unauthenticated Microsoft endpoints and standard DNS records. All data returned is publicly accessible to any internet user. It is designed for legitimate security research, penetration testing with authorisation, red team reconnaissance, M&A diligence, and third-party risk assessments. Do not use this tool to facilitate unauthorised access to any Microsoft tenant or cloud service. Lookups are rate-limited and logged anonymously for abuse prevention.
From just a domain, TenantRecon maps the externally-visible footprint of an organization's Microsoft 365 / Azure AD tenant: tenant ID, initial onmicrosoft.com domain (when DKIM is enabled), namespace and federation type, Intune MDM enrollment, Teams SIP, Exchange Online presence, a graded email-security posture (SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI, DNSSEC), Google Workspace usage, and 35+ other SaaS signals — all from public, unauthenticated endpoints.
Often, yes. Microsoft retired unauthenticated multi-domain enumeration in 2025 (MC1081538), so sibling domains can no longer be listed. But when a tenant has DKIM enabled, its selector1._domainkey CNAME points into
It is a heuristic 0–100 score derived only from public DNS: SPF (and its all mechanism), DMARC policy/pct/sp, whether DKIM selectors are published, MTA-STS, TLS-RPT, BIMI, and DNSSEC signing. It maps to an A+–F grade with specific recommendations. It is a fast posture indicator, not a substitute for a full email-authentication audit.
TenantRecon only queries publicly exposed, unauthenticated endpoints and standard DNS records that any client uses during normal sign-in and mail discovery — no credentials, exploitation, or unauthorized access. It is intended for defenders, red teamers, and researchers assessing their own or authorized targets.
No. TenantRecon is free, runs in the browser, and needs no sign-up or API key. Results can be exported as Markdown, CSV, or JSON.