Skip to main content

Red Sift Brings Domain Security Checks to Claude and ChatGPT — For Free

Ilustrační obrázek
Red Sift, the London-based email security company, just shipped native integrations that let security teams run domain vulnerability checks inside Claude and ChatGPT — without opening another tool. Behind the launch is a brutal economic reality: attackers now use large language models to cut the price of building a phishing campaign by 95 % down to roughly $1,500 (≈€1,380), while the business on the receiving end can burn close to $1 million (≈€918,000) fighting it. The Radar Lite integration is Red Sift's answer to that gap — a free layer that turns the assistant your team already has open into a domain security scanner.

The cost gap that forced this launch

Email security has always been asymmetric: the attacker only needs to succeed once, the defender needs to stop everything. AI just made that asymmetry worse. Gartner estimates that large language models have slashed the cost of building spam and phishing campaigns by 95 %. Verizon's 2026 Data Breach Investigations Report found that the average threat actor now uses AI across 15 different techniques to assemble an attack — from generating convincing lures to automating reconnaissance against target domains.

Rahul Powar, Red Sift's CEO and co-founder, put the numbers bluntly: a campaign that costs a spammer around $1,500 to launch can cost the business on the receiving end close to $1 million to defend against, if the response is slow. Converted to Euros at the current rate (≈€1,380 to attack, ≈€918,000 to defend), that is a cost multiplier of roughly 665×.

"Attackers adopted AI faster than most defenders, and the cost gap is the whole story," Powar said. "Radar isn't a rip-and-replace for your security stack. It's the AI layer that plugs into the workflows your team already built."

What the integrations actually do

Red Sift Radar is the company's LLM-powered security engine, embedded across its OnDMARC, Brand Trust, Certificates, and ASM products. Radar Lite is the free, standalone version that runs a security assessment on any domain and benchmarks the results against industry peers.

The two new integrations — rolled out July 29 — connect Radar Lite directly into Claude and ChatGPT:

  • You type a plain-language query like "Is my domain securely configured?" or "Check the DMARC setup for example.com" directly into the chat assistant.
  • Radar Lite runs checks across email authentication (SPF, DMARC, BIMI, MTA-STS), DNS configuration (DNSSEC, DANE, CAA records), TLS certificate validity, and web security headers (CSP, HSTS, SRI).
  • The result comes back as a plain-English summary with prioritised findings — no tool-switching, no login, no syntax-hunting.

On the ChatGPT side, Radar Lite appears in the official plugin directory. Claude users add it as an MCP (Model Context Protocol) connector via https://radar-lite.redsift.cloud/app/mcp — paste the URL in Claude's Settings → Integrations, confirm, and the tool is available in every new conversation.

The critical design decision here is that Radar Lite is opt-in, not a project. You are not procuring a new platform, training staff, or integrating into a SIEM. You switch it on inside the chat window your team already uses for code review, report drafting, and troubleshooting. That design philosophy — security where people already work — is what separates this from the last wave of threat-intelligence toolbars and browser extensions.

What this means for European companies

Red Sift is headquartered in London, which means the company operates under a UK GDPR adequacy decision that the European Commission renewed in 2025. That matters when you are piping domain configuration data through an AI assistant: the plugin runs checks against publicly resolvable DNS records, TLS certificates, and web headers — not internal traffic — so the surface for data exposure is limited by design. Still, European security teams should verify that no internal domain names or configurations leak into chat sessions that may be subject to AI provider logging policies.

The NIS2 directive, which EU member states are in the process of transposing into national law through 2026, imposes stricter incident-reporting and supply-chain security obligations on essential and important entities. Radar Lite's free benchmarking — which compares your domain posture against industry peers — maps directly onto the kind of continuous security monitoring that NIS2 auditors will look for. Being able to demonstrate that you regularly check your domain's SPF and DMARC configuration inside a tool your team already uses lowers the compliance friction.

For smaller European companies without dedicated security staff — roughly 60–80 % of EU SMEs, depending on the member state — the integration's value is straightforward: it gives a non-specialist a way to answer the question "are we configured correctly?" without needing to understand the 47-page DMARC RFC. That is the difference between having DMARC at p=none (monitoring only, which blocks nothing) and p=reject (full enforcement), a gap Red Sift's own research has documented across European markets.

Where the integration fits — and where it does not

Radar Lite is a free-tier tool. It runs a snapshot scan. It will tell you your SPF record has a syntax error, your TLS certificate expires in 14 days, or your DMARC is set to "none" while your industry peers enforce at 63 %. It will not give you ongoing monitoring, historical trend data, or integration with your SIEM — those are features of the paid Red Sift Radar platform.

For an independent developer running a SaaS from a VPS in Frankfurt, Radar Lite inside ChatGPT is probably sufficient: check your domain once a week, fix what it flags. For a mid-market company with 200 employees, multiple domains, and an upcoming NIS2 audit, the free integration is a sensible entry point — but it should lead to the full platform if you need automated alerts and remediation workflows.

One gap worth noting: the Claude integration currently uses MCP, which means it requires a Claude Pro or Team plan (the free tier does not support custom MCP connectors). ChatGPT's plugin directory requires a ChatGPT Plus subscription. So "free" is accurate for the Radar Lite service itself, but both assistants charge for the layer that hosts it.

Does Radar Lite share my domain data with OpenAI or Anthropic?

Radar Lite processes publicly available DNS and web configuration data through Red Sift's own API. The assistant (ChatGPT or Claude) acts as the interface, not as the data processor. Red Sift states it does not use customer data for model training. However, the text of your queries and responses does pass through the AI provider's infrastructure — so do not paste internal hostnames or non-public infrastructure details into the chat.

How does this differ from asking ChatGPT directly about my domain's security?

A plain ChatGPT query without Radar Lite will give you generic advice about what DMARC or SPF does — the kind of answer that reads like a Wikipedia summary. It cannot actually look up your domain's live DNS records, check your TLS certificate validity, or benchmark your configuration against real industry data. Radar Lite does the actual network queries and returns specific, verifiable results tied to your domain.

Do I need a paid Red Sift account to use this?

No. Radar Lite is free. You do however need a ChatGPT Plus subscription (for the plugin directory) or a Claude Pro/Team plan (for MCP connector support) — because the assistants themselves gate their plugin and integration layers behind paid tiers.

X

Don't miss out!

Subscribe for the latest news and updates.