External attack surface report
What the internet can see of trusteed.io
Every subdomain, IP, open port and running product visible from outside — with known CVEs as a secondary pass, not the whole report.
Comparable companies in your sector average 78. Fixing the two critical items alone moves you to roughly 84.
- Domain
- trusteed.io
- URL
- https://www.trusteed.io/
- IP address
- 104.21.53.150
- Cloud provider
- Cloudflare
- Location
- US
- ASN
- AS13335 Cloudflare
- Website title
- trusteed.io — public website
- Description
- Public marketing and product surface for trusteed.io, reachable without authentication.
- DNS A records
- 104.21.53.150 · 172.67.247.90
- DNS MX records
- 10 mail.trusteed.io
- DNS NS records
- ns1.cloudflare.com · ns2.cloudflare.com
Every hostname that publicly resolves under your domain. Anything here can be reached from the internet, whether you meant to publish it or not.
trusteed.io104.21.53.150Marketing siteProtectedwww.trusteed.io104.21.53.150Marketing siteProtectedapp.trusteed.io172.67.247.90Customer appProtectedapi.trusteed.io46.101.187.30Public APIExposed directmail.trusteed.io46.101.187.30Mail serverNeeds reviewstaging.trusteed.io46.101.187.30Pre-productionShould be privatevpn.trusteed.io185.42.127.224Remote accessNeeds reviewold-blog.trusteed.io46.101.187.30UnmaintainedLikely forgottenPublic addresses that hostnames under this domain resolve to.
104.21.53.150trusteed.io, www, appCloudflareCDN edge46.101.187.30api, mail, staging, old-blogDigitalOceanOrigin185.42.127.224vpn.trusteed.ioUnknownNeeds reviewOpen doors on your public IPs. Web and mail ports are expected — admin and database ports usually are not.
104.21.53.150:443HTTPSWebsite trafficYes — expected104.21.53.150:80HTTPRedirect to HTTPSYes — expected46.101.187.30:22SSHServer administrationNo — restrict to VPN46.101.187.30:3306MySQLDatabaseNo — close now46.101.187.30:25SMTPSending mailYes — but harden185.42.127.224:8080HTTP altAdmin panelNo — needs authSoftware an attacker can fingerprint from outside. Versions matter — old versions are how most breaches start.
Cloudflare—trusteed.ioCurrentnginx1.18.0api, staging2 years behindWordPress6.3.2old-blog6 releases behindOpenSSH8.2p146.101.187.30Update availablePHP7.4.33old-blogEnd of lifeNext.js14.2.3appCurrentKnown CVEs matched to the products above. This is a small slice of the surface map — exploitability first, not a full scanner dump.
CVE-2024-4577PHP 7.4.33Yes — active campaignsFix todayCVE-2023-44487nginx 1.18.0Yes — HTTP/2 rapid resetFix this weekSee trusteed through the eyes of threat actors
Continuous discovery across every subdomain, IP, port and product. The free plan keeps watching one domain and only alerts when the surface actually changes.