Back to knowledge base

internet.nl is free. So when do you need Exposentry?

Published on July 3, 2026 · Updated on August 4, 2026

If you want to run one free test on your domain, internet.nl is a fine choice. It is a Dutch public-private service for internet standards, an initiative of the Platform Internetstandaarden, and it neatly checks whether your domain supports modern internet standards. We recommend it ourselves.

So why does Exposentry exist? Because a standards check and an evidence file are two different things. This article explains the difference, so you know when free is enough and when it is not. Full transparency: the measurement layer beneath Exposentry is OpenKAT, the Dutch government's open-source security scanner, and Edward Hasekamp (founder of Exposentry) contributes to that codebase as a collaborator. internet.nl and OpenKAT are two separate Dutch initiatives; we are not borrowing the credibility of one to sell the other.

In short

  • internet.nl is an excellent free check on internet standards: among others IPv6, DNSSEC, TLS, RPKI, security.txt and mail security. Use it.
  • The free web test is a snapshot; the internet.nl Dashboard can measure periodically and automatically, track multiple domains and build history. But both measure standards only; your attack surface and new vulnerabilities stay out of view.
  • It tests standards only: no CVE detection, no attack surface, no forgotten subdomains.
  • It produces no signed evidence file: no tamper-evident, per-finding documented report that a third party can independently verify and that is delivered to you as the client separately from the party managing your environment.

What internet.nl does well

internet.nl tests whether your domain, website and mail use the modern, open standards that make the internet safer: among others IPv6, DNSSEC, HTTPS with a solid TLS configuration (including HSTS, STARTTLS and DANE), RPKI, security.txt, and mail standards like SPF, DKIM and DMARC. The result is a clear percentage with concrete improvements.

For basic standards hygiene there is no reason to pay. If you score poorly there, start there; those are often the cheapest improvements with the most effect.

Where the line is

The free web test answers the question "where do I stand on standards right now?" The internet.nl Dashboard (on the batch API) goes further: it measures periodically and automatically, tracks lists of up to thousands of domains, builds a timeline with history across multiple measurements and sends notifications on changes. Even so, there are five things the Dashboard also does not do, and they are exactly what matters once someone else asks you for evidence.

  1. Attack surface rather than standards. The Dashboard periodically re-tests the standards on the domains you put on a list yourself. What it does not do is continuously track your attack surface: a new or forgotten subdomain, a service accidentally left open, a vulnerability that becomes known today. Exposentry flags that the moment it happens.
  2. CVE detection. Standards say nothing about known vulnerabilities in your software. A domain can score 100% on internet.nl while running an outdated application with an actively exploited CVE. What is visible from the outside is covered in what does an attacker see of your domain.
  3. Signed, verifiable evidence. internet.nl gives you a dated, shareable result page with a permalink, and that is more than a screenshot. But it is not a signed, per-finding documented file that a third party can independently verify. Exposentry records per finding how and when it was established, in signed and timestamped reports that are tamper-evident. See how to check whether a security report is real.
  4. History as an evidence file. The Dashboard builds a timeline of your standards scores across multiple measurements, and that is useful. An auditor or insurer also wants to know whether you paid attention to vulnerabilities all year and what you did with findings, recorded in a signed file you can hand over. That is a different timeline than a series of standards scores. Why that is, is covered in forensically grounded evidence.
  5. Independent reporting. Evidence for third parties carries more weight when it goes directly from the measuring party to the client, not through the party that manages the environment; with many auditors and insurers it counts as stronger evidence. Why that matters is covered in independent reporting.

The honest decision rule

Use internet.nl when nobody is asking for evidence and you want to know where you stand on standards. For many small organizations that is enough for a long time.

Look at Exposentry as soon as one of these three situations applies: a large customer sets requirements under the NIS2 supply chain duty of care, an auditor or regulator wants to see demonstrable vulnerability management, or a cyber insurer asks for substantiation at acceptance or claim time. In all three cases the question is not "did you test?" but "can you prove it?" And that is a different service than a free check, however good that check is.

Written by Edward Hasekamp, founder of Exposentry and collaborator on the open-source OpenKAT project. See the project on GitHub and the profile at github.com/hasecon. Exposentry provides EU-sovereign, forensically substantiated vulnerability monitoring based on OpenKAT. More articles in the Knowledge base.