Skip to main content

recon

CI PyPI Python License OpenSSF Scorecard

Point recon at a domain and get its public technology and identity footprint: email security, mail and identity providers, SaaS indicators, and certificate-transparency findings. No credentials, no API keys, no active scanning. Ships as a CLI, versioned JSON, and a local MCP server for agent tools. About ten seconds per domain.

Defensive use only. Posture review, vendor diligence, architecture review. See docs/legal.md.

Quick Start

Install and check the version offline:

uv tool install recon-tool    # or: pipx install recon-tool
recon --version               # offline check

Python 3.11 through 3.14, on Windows, macOS, or Linux. recon doctor tests online connectivity to recon's public data sources.

Optional install helpers at scripts/install.ps1 and scripts/install.sh drive an existing uv or pipx installation. Download a release-tag source archive, review the helper locally, then run it: each installs the exact version represented by that tag, preserves a sole existing owner, and refuses ambiguous or unmanaged installations. Do not pipe mutable branch content into a shell. To verify published artifacts first, follow the consumer verification recipe.

Before the first lookup, know what leaves your machine. recon makes DNS queries that recursive and authoritative DNS infrastructure may observe. Its only default request to a target-owned endpoint is the standards-defined MTA-STS policy fetch; Google CSE and BIMI certificate probes run only when --direct-probes is explicitly enabled. See ADR-0011.

recon example.com

Every lookup is live. recon ships no offline demo mode, so reserved names such as example.com return a panel of stray public residue from unrelated test configurations, including a meaningless display name, at High confidence. It shows you the shape of the output, not a result about any organization. Point recon at a domain you operate or are authorized to review to see a real footprint.

A domain is a query coordinate, not proof of one organization or product: recon reports observations, not verdicts. That is the caution to keep beside every row the panel shows.

Illustrated output (synthetic, not a captured run)

Synthetic terminal showing recon's default output

The panel above is generated, not captured: scripts/generate_terminal_demo.py drives recon's real formatter over a deterministic, no-network fixture for the fictional Example Industries Ltd. It shows the shape of a full-signal result, every row a rich target can fill, and no live lookup of reserved example.com reproduces it. No real organization is depicted. Other project fixtures use IETF reserved .invalid namespaces.

Accessible text transcript
$ recon example.com    # synthetic fixture, not a captured run
Example Industries Ltd
example.com
──────────────────────────────────────────────────────────────────────────────
  Provider     Microsoft 365 + Proofpoint gateway
  Tenant       a1b2c3d4-e5f6-7890-abcd-ef1234567890 • NA
  Tenant domain example-industries.onmicrosoft.example.com
  Auth         Federated
  Confidence   ●●● High (4 sources)


Services
  Email            Microsoft 365, Proofpoint, DMARC reject, DKIM,
                   SPF strict, MTA-STS enforce
  Identity         Okta
  Cloud            Cloudflare (CDN/edge), AWS Route 53 (DNS)
  Security         Wiz Security
  Data & Analytics Snowflake, Datadog
  Collaboration    Slack, Atlassian (Jira/Confluence), GitHub, Zoom
                   Evidence roles: --explain


High-signal related domains
  login.example.com, support.example.com, status.example.com

Insights
  Federated identity observed; identity-vendor indicators: Okta
  Email security: observed controls: DMARC reject, DKIM, SPF strict, MTA-STS

Install, update, uninstall, and first-run detail: docs/getting-started.md.

What recon Is Good For

Need Use recon for Use something else when
Fast external stack context Passive DNS, identity-endpoint, CT, SaaS, and posture indicators You need authenticated tenant inventory or asset-management truth
Defensive review or vendor diligence Hedged observations and evidence traces you can verify You need vulnerability scanning, exploit checks, or host-level facts
Automation-friendly output Stable JSON, batch mode, delta mode, and local MCP tools You need dashboards, scheduling, or report generation built in

recon reports observations, not verdicts. Public channel ceiling: docs/limitations.md. How to report a result without overstating it: docs/reporting-observations.md.

v2.15 and v2.16 closed a five-round presentation-drift class. Independent testers installed the published package, never read the source, and kept finding the same issue: a decision applied to one renderer and not the others. The engine is feature-complete. Those findings and their fixes are in CHANGELOG.md and in ADR-0015 through ADR-0017.

The living work is the fingerprint catalog. Vendors add, rename, and retire the public patterns recon detects, so a rule with no re-check is a slow source of false positives and negatives. Most useful contributions are one YAML file, not code: a current vendor-documentation page (or a disclosure-safe aggregate basis), a verified date, a fictional positive, and a lookalike negative. CONTRIBUTING.md has the schema, the validation command, and what is deliberately out of scope. The freshness loop and its coverage floor live in docs/catalog-strategy.md.

Common Commands

recon example.com                              # default panel
recon example.com --explain                    # evidence trail
recon example.com --gaps                       # neutral hardening prompts
recon example.com --plain                      # panel as linear text (screen readers, grep)
recon example.com --plain --full               # every field, linear
recon example.com --json                       # structured record
recon example.com --explain-dag --explain-dag-format mermaid   # evidence DAG
recon batch domains.txt --json                 # batch JSON array
recon delta example.com                        # diff vs local cache
recon capsule capture example.com -o run.json  # caller-owned replay artifact
recon mcp install --client=cursor              # wire MCP into a client

More flags: docs/cli-surface.md. JSON contracts: schema · stability · operational contract.

Versioned JSON remains recon's structured runtime contract. The Open Knowledge Format v0.2 projection is deferred until a named consumer justifies the mapping. recon does not emit OKF, and any future OKF view would be additive rather than a replacement for JSON. Caller-owned JSON observation capsules are documented in docs/observation-capsules.md, with the decision boundary in ADR-0014.

docs/surface-inventory.json, docs/cli-surface.md, and recon://surface-inventory are generated discovery context and drift guards, not stable runtime API contracts. ADR-0007 records the promotion gate.

Use with an AI agent (plugin / MCP / skill)

Wire recon into Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, Kiro, or any MCP-compatible client:

recon mcp install --client=claude-desktop
# also: claude-code, cursor, vscode, windsurf, kiro
recon mcp doctor

Start with manual tool approvals. Treat agents as untrusted input. Full setup: docs/mcp.md. Per-client scaffolds and skills: agents/.

The current scaffolds use each client's native configuration. In particular, the bundled Claude Code plugin uses Claude Code's client-specific layout; it does not claim conformance with the portable Agent Plugins v1.0.0 specification. A complete-surface portable candidate now lives under agents/agent-plugin/ and passes network-free validation against the exact pinned v1.0.0 schemas, whose bytes still match the Published specification. That is not a client compatibility or conformance claim. The frozen VS Code, Cursor, and Kiro preflight now passes, but the paired evaluation remains incomplete. Until that evaluation passes, use the documented client-specific install path above.

You say What the agent should do
"Recon example.com" Call lookup_tenant (or recon example.com) and return the panel-style summary
"What does example.com run for email and identity?" Same lookup; lead with MX/IdP/tenant facts and confidence
"Why do you think that?" Re-run with explain / provenance (--explain or explain=true)
"Compare example.com and example.net" compare_postures or two lookups side by side
"Any public hardening gaps?" find_hardening_gaps after a lookup - hedged "Consider" notes only

Example chat. This transcript uses the same synthetic Example Industries fixture as the illustration above, so it shows the shape of a full-signal answer rather than what a live example.com lookup returns:

You: Recon example.com and tell me what you observe.

Agent: Public evidence for example.com (fictional demo):

  • Mail: Microsoft 365 delivery path plus Proofpoint gateway; DMARC p=reject, SPF strict, MTA-STS enforce.
  • Identity: Federated; Okta indicator via CNAME.
  • Tenant: GUID present, region NA; confidence high from four sources.
  • Also seen: Cloudflare and Route 53 infrastructure, Wiz, Snowflake, Datadog, Slack, Atlassian, GitHub, and Zoom public indicators.

These are public-record observations, not a security grade or proof of active product use. Say if you want evidence detail or a gap review.

Guidance: agents/claude-code/skills/recon/, AGENTS.md.

Optional Cloud Access

Local execution is the default, and the project does not operate a hosted service. For teams that want shared remote access, the repository includes a draft authenticated container and Cloud Run Terraform starting point. It is intended to be directionally useful, not a validated production deployment. Operators own deployment, identity, data handling, cost, and operations.

Docs

Topic Link
Glossary of recon's terms docs/glossary.md
Install and first commands docs/getting-started.md
Reporting a result without overstating it docs/reporting-observations.md
How it works docs/how-it-works.md
Known weak areas and conservative wording docs/weak-areas.md
Catalog growth and freshness loop docs/catalog-strategy.md
Observation capsules docs/observation-capsules.md
Correlation model docs/correlation.md
MCP and agents docs/mcp.md, agents/
Full docs index docs/README.md
Roadmap ROADMAP.md · docs/roadmap.md · docs/strategic-gap-audit.md
Changelog CHANGELOG.md
Security SECURITY.md · docs/security.md

Research and publication pointers (maintainer track, not the product core): docs/submission-freeze-checklist.md, validation/2026-06-30-submission-freeze-local-proof.md, docs/public-label-snapshot-decision.md (public lists as robustness checks rather than population rates), and docs/m365-tenancy-decision.md.

Development

The repository requires uv >=0.11.8,<0.12; CI currently pins 0.11.17.

uv sync
uv run pre-commit install
uv run python scripts/release_readiness.py --allow-dirty
uv run python scripts/check.py

uv run python scripts/check.py is the canonical local gate: lint, type checks, coverage-gated tests, generated-artifact and catalog checks, text and link hygiene, interface and claim checks, and size and complexity ratchets. Green locally means green in CI.

Project hygiene: keep examples reserved and synthetic, keep validation artifacts aggregate-only, and avoid dead code or placeholders. See CONTRIBUTING.md.

License

Apache 2.0. Free to use, build on, fork, and share. See LICENSE for the full terms.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

recon_tool-2.17.5.tar.gz (3.3 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

recon_tool-2.17.5-py3-none-any.whl (786.4 kB view details)

Uploaded Python 3

File details

Details for the file recon_tool-2.17.5.tar.gz.

File metadata

  • Download URL: recon_tool-2.17.5.tar.gz
  • Upload date:
  • Size: 3.3 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for recon_tool-2.17.5.tar.gz
Algorithm Hash digest
SHA256 4034f96acc235f9a30be84a50387fe0ec4d1da63f609859d23a27caad3d2b58c
MD5 d38421ab98147e0a44bc933b7b695a94
BLAKE2b-256 f5831cfce80806b66ceee1e3ebb697858b540d6e54d430298e39c478b7aba76c

See more details on using hashes here.

Provenance

The following attestation bundles were made for recon_tool-2.17.5.tar.gz:

Publisher: release.yml on blisspixel/recon

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file recon_tool-2.17.5-py3-none-any.whl.

File metadata

  • Download URL: recon_tool-2.17.5-py3-none-any.whl
  • Upload date:
  • Size: 786.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for recon_tool-2.17.5-py3-none-any.whl
Algorithm Hash digest
SHA256 258196c054c8a6da84fdcfe9773ac216520e85a27f0bc7de014164d539906e62
MD5 aadef8fd534703624944dada103453fa
BLAKE2b-256 8e0aa240b440bcd6383db4c963d32331903e7200628525681fdbd3b0fede897e

See more details on using hashes here.

Provenance

The following attestation bundles were made for recon_tool-2.17.5-py3-none-any.whl:

Publisher: release.yml on blisspixel/recon

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

2.18.4

2 files

2.18.3

2 files

2.18.2

2 files

2.18.1

2 files

2.18.0

2 files

2.17.13

2 files

2.17.12

2 files

2.17.11

2 files

2.17.10

2 files

2.17.9

2 files

2.17.8

2 files

2.17.7

2 files

2.17.6

2 files

This release

2.17.5 This release

2 files

2.17.4

2 files

2.17.3

2 files

2.17.2

2 files

2.17.1

2 files

2.17.0

2 files

2.16.1

2 files

2.16.0

2 files

2.15.1

2 files

2.15.0

2 files

2.14.1

2 files

2.14.0

2 files

2.13.0

2 files

2.12.0

2 files

2.10.4

2 files

2.10.3

2 files

2.10.2

2 files

2.10.1

2 files

2.10.0

2 files

2.9.0

2 files

2.8.0

2 files

2.7.0

2 files

2.6.14

2 files

2.6.13

2 files

2.6.12

2 files

2.6.11

2 files

2.6.10

2 files

2.6.9

2 files

2.6.7

2 files

2.6.6

2 files

2.6.5

2 files

2.6.4

2 files

2.6.3

2 files

2.6.2

2 files

2.6.1

2 files

2.6.0

2 files

2.5.8

2 files

2.5.7

2 files

2.5.6

2 files

2.5.5

2 files

2.5.3

2 files

2.5.2

2 files

2.5.1

2 files

2.5.0

2 files

2.4.0

2 files

2.3.9

2 files

2.3.8

2 files

2.3.7

2 files

2.3.6

2 files

2.3.5

2 files

2.3.4

2 files

2.3.3

2 files

2.3.2

2 files

2.3.1

2 files

2.3.0

2 files

2.2.19

2 files

2.2.18

2 files

2.2.17

2 files

2.2.16

2 files

2.2.15

2 files

2.2.14

2 files

2.2.13

2 files

2.2.12

2 files

2.2.11

2 files

2.2.10

2 files

2.2.9

2 files

2.2.8

2 files

2.2.7

2 files

2.2.6

2 files

2.2.5

2 files

2.2.4

2 files

2.2.3

2 files

2.2.2

2 files

2.2.1

2 files

2.2.0

2 files

2.1.18

2 files

2.1.17

2 files

2.1.16

2 files

2.1.15

2 files

2.1.14

2 files

2.1.13

2 files

2.1.12

2 files

2.1.11

2 files

2.1.10

2 files

2.1.9

2 files

2.1.8

2 files

2.1.7

2 files

2.1.6

2 files

2.1.5

2 files

2.1.4

2 files

2.1.3

2 files

2.1.2

2 files

2.1.1

2 files

2.1.0

2 files

2.0.1

2 files

2.0.0

2 files

1.9.99

2 files

1.9.98

2 files

1.9.97

2 files

1.9.96

2 files

1.9.95

2 files

1.9.94

2 files

1.9.93

2 files

1.9.92

2 files

1.9.91

2 files

1.9.90

2 files

1.9.89

2 files

1.9.88

2 files

1.9.87

2 files

1.9.86

2 files

1.9.85

2 files

1.9.84

2 files

1.9.83

2 files

1.9.82

2 files

1.9.81

2 files

1.9.80

2 files

1.9.79

2 files

1.9.78

2 files

1.9.77

2 files

1.9.76

2 files

1.9.75

2 files

1.9.74

2 files

1.9.73

2 files

1.9.72

2 files

1.9.71

2 files

1.9.70

2 files

1.9.69

2 files

1.9.54

2 files

1.9.53

2 files

1.9.52

2 files

1.9.51

2 files

1.9.50

2 files

1.9.49

2 files

1.9.48

2 files

1.9.47

2 files

1.9.46

2 files

1.9.45

2 files

1.9.44

2 files

1.9.43

2 files

1.9.42

2 files

1.9.41

2 files

1.9.40

2 files

1.9.39

2 files

1.9.38

2 files

1.9.37

2 files

1.9.36

2 files

1.9.35

2 files

1.9.34

2 files

1.9.33

2 files

1.9.32

2 files

1.9.31

2 files

1.9.30

2 files

1.9.29

2 files

1.9.28

2 files

1.9.27

2 files

1.9.26

2 files

1.9.25

2 files

1.9.24

2 files

1.9.23

2 files

1.9.22

2 files

1.9.21

2 files

1.9.20

2 files

1.9.18

2 files

1.9.14

2 files

1.9.13

2 files

1.9.12

2 files

1.9.11

2 files

1.9.10.1

2 files

1.9.10

2 files

1.9.9

2 files

1.9.8

2 files

1.9.7

2 files

1.9.6

2 files

1.9.5

2 files

1.9.4

2 files

1.9.3.10

2 files

1.9.3.9

2 files

1.9.3.8

2 files

1.9.3.7

2 files

1.9.3.6

2 files

1.9.3.5

2 files

1.9.3.4

2 files

1.9.3.3

2 files

1.9.3.2

2 files

1.9.3.1

2 files

1.9.3

2 files

1.9.2.2

2 files

1.9.2

2 files

1.9.1

2 files

1.9.0

2 files

1.8.1

2 files

1.8.0

2 files

1.7.0

2 files

1.6.1

2 files

1.6.0

2 files

1.5.2

2 files

1.5.1

2 files

1.5.0

2 files

1.4.8

2 files

1.4.7

2 files

1.4.6

2 files

1.4.5

2 files

1.4.4

2 files

1.4.3

2 files

1.4.2

2 files

1.4.1

2 files

1.4.0

2 files

1.3.1

2 files

1.3.0

2 files

1.2.1

2 files

1.2.0

2 files

1.1.0

2 files

1.0.2

2 files

1.0.1

2 files

1.0.0

2 files

0.11.0

2 files

0.10.3

2 files

0.10.2

2 files

0.10.1

2 files

0.10.0

2 files

0.9.3

2 files

0.9.2

2 files

0.9.1

2 files

0.9.0

2 files

0.8.1

2 files

0.8.0

2 files

0.7.3

2 files

0.7.2

2 files

0.7.1

2 files

0.7.0

2 files

0.6.1

2 files

0.6.0

2 files

0.5.1

2 files

0.5.0

2 files

0.4.1

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page