Which software does your competitor use?
Enter any company’s website. We read their public DNS records, email configuration and careers page, and report which CRM, HRMS, applicant tracking, helpdesk and billing software they appear to run — along with the evidence for every conclusion.
Reads only public DNS records and public web pages. No login, no port scanning.
How this works
DNS and CNAME records
We resolve around 200 common hostnames — hrms, careers, crm, support, billing and so on. When one points at a vendor's cloud (careers.acme.com → acme.myworkday.com), only Acme's own DNS administrator could have created that record, and it names the vendor outright.
SPF and email records
A company's SPF record lists every service authorised to send mail on its behalf. It is the single richest stack signal available publicly, and it routinely names the CRM, the marketing platform and the HR system in one line.
The careers page
Almost every applicant tracking system is embedded or linked directly from a public careers page. The ATS in turn is a strong indicator of the wider HR stack, because most vendors sell both.
Public page signatures
Scripts, cookies and form endpoints on the public website identify chat widgets, analytics and marketing automation. We weight these lowest — a widget on a website is not proof of what runs the business.
Questions people ask
How does App Advisor work out which software a company uses?
We read five kinds of publicly published infrastructure metadata: DNS CNAME records on common subdomains (a hrms.example.com pointing at example.darwinbox.in is a Darwinbox tenant), SPF records that list which SaaS vendors may send email as the company, MX records that reveal the email platform, the ATS embedded in the public careers page, and script, cookie and form signatures on the public website. Every detection is shown with the exact record we matched.
Is this legal?
Yes. Everything we read is published deliberately by the domain owner and served to any anonymous visitor — DNS records are a public directory, and the pages we fetch are the same ones your browser downloads. We do not log in, bypass any access control, scan ports, or probe for vulnerabilities. We identify our crawler honestly and obey robots.txt.
How accurate is it?
It depends on the signal. A CNAME or SPF match is close to conclusive because only the domain's own administrator can create one. A script or cookie match is weaker — a marketing widget on a website is not proof the company runs that product internally. We publish a confidence score and the underlying evidence for every result so you can judge for yourself, and we never report a detection as certain.
Why would I want to know this?
Because 'what do companies like mine actually run' is a better starting point than a feature matrix. If four of your five closest competitors run the same HRMS, that tells you something a vendor's pricing page never will — and if they are all on something you have outgrown, that is an opening.
What if you find nothing?
Some companies self-host, sit entirely behind a CDN that masks origin records, or run on-premise software with no public footprint. In those cases we say so plainly rather than guessing. An empty result is a real answer, not a failure.