About surfer
surfer is a defensive asset-inventory tool. Given the domains an organisation is authorised to inventory, it lists the hostnames that look like internet-facing web applications, APIs, webhooks and MCP endpoints, so that stale or unmanaged ones can be found, decommissioned, made private or IP-restricted.
The passive-only promise
surfer uses public passive data only. It never connects to the hosts it lists.
- It reads public Certificate Transparency data (the search services crt.sh and Certspotter) to learn which hostnames appear on publicly logged certificates.
- It makes ordinary DNS lookups (A, AAAA and CNAME) through a recursive resolver. The name servers of a domain see only routine resolver traffic.
- It sends no TCP, TLS, HTTP or ICMP traffic to any discovered host or IP address. It does not scan ports or address ranges, guess names from wordlists, brute-force, fuzz or check for vulnerabilities.
Results are candidates with evidence and a confidence score, not confirmed-live applications.
Accountable use
Before adding a domain, a user must confirm they are authorised to inventory it on behalf of their organisation. Every submission is audit-logged per organisation, and quotas, rate limits and abuse review apply.
How surfer identifies itself
Requests to the Certificate Transparency search services carry this User-Agent, which points back to this page:
surfer/<version> (+https://<this site>/about)
surfer sends nothing to your servers, so you will not see this User-Agent in your own web server logs.
Opt-out and contact
If you control a domain and do not want it inventoried, or you believe it was submitted by someone who is not authorised, write to abuse@northkeel.tech with the domain name. We will remove it from every organisation's inventory and block further submissions of it.