Security and privacy decision

Authex

A competent developer can build a useful scanner/monitor (the core monitoring and workspace read-only posture) in a few weeks, but Authex's value relies on its large proprietary corpus and autonomous enforcement features which are hard to replicate.

Visit website
You pay

$19/mo

$228/yr

Read off the official pricing page.

You’d pay instead

$100one-off120 h to build

$150/mo6 h/mo upkeep

On cash alone, building overtakes the subscription at 9 seats.

No open-source build does this yet

Nothing published replaces this one, so a replacement starts from an empty file. Here is what it would have to cover.

What a replacement has to do

  • Periodically fetch public DNS and protocol endpoints for a domain, evaluate six email-protection signals, surface findings in a dashboard, and (optionally) connect read-only to Google Workspace / Microsoft 365 to collect mailbox/workspace posture data.

What it still won’t have

  • Authex's 4M+ publicly observed domains research corpus and historical internet-scale observations
  • Autonomous enforcement agent that advances policies and performs managed changes
  • MSP-focused multi-customer billing, roles and per-customer isolation polish
  • Built-in auditor evidence packs mapped to frameworks

What remains hard

  • Proprietary dataAuthex tracks 4M+ publicly observed domains across 189 countries. Corpus data is separate from customer usage.
Read the build prompt

First-year cost

Keep paying

Paying is—cheaper in year one.

On cash alone, building overtakes the subscription at 9 seats.

Paid seatsseats

Money you would actually spend

Keep paying
—

Subscription price × seats × 12

Build it
—

AI build —APIs + hosting —

Time you would spend

—

—

What you would spend

What we assumed

The verdict above measures whether you could build it. This one is only about money.

Runnable build prompt

Not run yet
Build a domain email-protection scanner and monitor service using Node.js (Express), Postgres, Redis, and a worker queue (BullMQ). Core features in scope: (1) DNS and protocol fetchers for SPF, DKIM, DMARC, MTA-STS, TLS-RPT and BIMI; (2) scheduled workers that run scans and store raw results and a computed protection score in Postgres; (3) read-only OAuth connectors for Google Workspace and Microsoft 365 to collect mailbox/posture metadata; (4) a simple policy store that records desired state, change history and exports an auditor evidence ZIP; (5) a web UI to view domains, scores, findings and download evidence; (6) tests for workers, API and scoring logic and basic error handling and retries. Out of scope: autonomous enforcement that writes DNS or makes mailbox configuration changes, multi-tenant MSP billing polish, and building a proprietary internet-scale corpus. Provide logging, retries, exponential backoff for external calls, and unit/integration tests.
How we checked2 sources · 3/3 runs agreed · evidence score 57

How the score was reached

  • Partly verdict base52
  • 2 cited sources+1
  • Price verified on pricing page+3
  • 3/3 assessment runs agreed+4
  • Hard moats found in the evidence-3
  • Evidence score57

The base comes from the verdict. Everything under it is a check that either happened or did not, and each one is a fact frozen in this record rather than a judgement made at render time - so the same evidence always produces the same number.

How scoring works →

Cited sources · 2

Every page the run actually retrieved.

Integrity checks

What held up, and what did not.

✓ Price read off the page✓ 3 independent runs, one answer✓ Citations limited to fetched pages! 1 moat quoted from the page