# Attack surface map — <organisation> — <YYYY-MM>

Source: https://mysecscan.com/learn/attack-surface-mapping
One row per hostname. Keep this file in version control; review monthly; the diff is your change report.

Columns
- hostname — fully qualified, lower-case
- target — A/AAAA address, or the CNAME target for third-party hosts
- owner — a person or team, never blank (blank = finding)
- purpose — one phrase
- decision — keep | retire | fix (dangling / misconfigured) | unknown
- tech — server / framework / CMS from headers and HTML
- score — Website Security Score grade (https://mysecscan.com/tools/website-security-score)
- monitored — yes/no (Domain Monitor or your own CT/RDAP watch)
- notes — decommission date, ticket, caveats

| hostname | target | owner | purpose | decision | tech | score | monitored | notes |
|---|---|---|---|---|---|---|---|---|
| www.example.com | 203.0.113.10 | web team | main site | keep | Next.js / Cloudflare | A | yes | |
| old.example.com | 203.0.113.11 | (none) | 2023 site | retire | WordPress 6.2 | D | no | no owner — delete by 2026-10-01 |
| help.example.com | CNAME acme.zendesk.com | support | helpdesk | keep | SaaS | n/a | yes | third-party |
| promo.example.com | CNAME pages.oldtool.io | (none) | old campaign | fix | — | — | no | dangling: target NXDOMAIN |
| mail.example.com | 203.0.113.20 | IT | mail | keep | Postfix | — | no | ports 25/587 only |

Zone-level facts (apex domain)
- MX:
- SPF (TXT):
- DMARC (_dmarc TXT):
- NS:
- Registrar / expiry:

Lookalike surface (not ours — from CT search for the brand without the dot, and RDAP)
| name | first seen | certificate / registrar | status | action |
|---|---|---|---|---|
| | | | | |
