FORTIBLEED · FORTIGATE EXPOSURE CHECK
Is your perimeter in the FortiBleed leak?
FortiBleed exposed verified FortiGate admin and VPN credentials for tens of thousands of firewalls worldwide. Check whether your own domain appears in the dataset — ownership-verified, with credentials never shown.
You can only see results for a domain you control. Next step verifies ownership via a DNS TXT record — no credentials are ever displayed.
Verify you own this domain
Add the following TXT record to , then confirm. This proves control of the domain and blocks anyone from checking a domain that isn't theirs.
PROCESS
Three steps, and nothing you don't control leaves the screen
Enter your domain
Type the domain you want to check. We match it against the FortiBleed dataset by registered account domain — never by scanning your network.
Verify ownership
Publish a one-time DNS TXT record we generate. Only someone who controls the domain's DNS can pass — so no one can probe a domain that isn't theirs.
Read your exposure
You get a yes/no result and how many of your hosts appear — as counts only. To act on it, request a full disclosure and our team walks you through response.
DATA HANDLING
What we never show
No credentials, ever
Passwords and login names from the leak are never displayed, exported, or returned by this tool — not even to a verified owner.
No IPs or emails in results
Results are aggregate counts for your domain. Individual device IPs and contact addresses are handled only through direct, verified disclosure.
Ownership-gated
Every result is locked behind DNS-based domain verification, so the tool can't be used to enumerate other organizations' exposure.
Handled as sensitive data
Records that touch EU-based assets are processed under applicable privacy law. Access is logged and rate-limited.
Confirmed exposed? Don't just rotate a password.
FortiBleed can't be fixed by patching alone. psymont helps you rotate every secret, hunt for persistence, and rebuild if needed — from first check to closed incident.