Welcome to the SecRift blog
A personal note from the founder on why SecRift exists, what you can scan today, and where we are taking it next.
Hi, I'm Mariusz Dalewski. I'm a security specialist, and day to day I run a company that delivers DevOps services. I built SecRift to scratch an itch I kept running into: checking whether a domain's security is actually configured correctly should be fast and straightforward, not an afternoon of manual lookups and half-remembered RFCs.
That's the whole idea behind SecRift - quick, no-nonsense security analysis of the parts of your infrastructure that are exposed to the world. You enter a domain, we audit its external surface, and you get a graded report with clear, prioritized findings. No agents to install, no accounts required to try it.
What you can scan today
Right now SecRift focuses on the email and DNS layer, where misconfigurations are common and quietly expensive. Every scan covers:
- Email authentication - SPF, DMARC, MTA-STS, TLS-RPT, and DANE, so you know whether your domain can be spoofed and whether mail to you is forced over TLS.
- DNS integrity - DNSSEC, so you can see whether your DNS answers are signed and tamper-evident.
Each check breaks down into specific findings with a plain-language explanation and a concrete fix, and every finding links to an article like the ones on this blog if you want to understand the technology behind it.
A couple of things make it practical beyond a one-off look:
- Private scans. Sign in and your scans are kept to your account, so you can run checks on the domains you manage without putting them on public display.
- PDF export. Export the whole result as a single report that shows everything at once - handy for handing a clear picture to a client, a colleague, or your own records.
Where we're taking it
This is the starting point, not the destination. We intend to keep expanding SecRift with additional checks, dedicated security tooling, and our own scanners built for the kinds of problems we run into in real engagements. The goal is a place where you can get a credible read on a system's security posture quickly, and then go deeper where it matters.
This blog is part of that. It's where we'll explain the technologies behind the checks, share what we learn, and walk through how to fix the issues SecRift surfaces - in language that's useful whether you're a security engineer or someone who just wants their domain to be safe.
If you'd like to reach me or follow along with where this is heading, you can find me on LinkedIn.
Thanks for being here this early. Run a free scan on any domain at secrift.com and see where your security stands.
- Mariusz


