Free tools No signup, no limits

Security tools we actually use.

Small, sharp tools for the work that fills a security day: reading a suspicious email, checking a policy before it ships, cleaning up indicators, pulling a token apart, seeing what your domain gives away. Free to use, and free of the usual catch.

Four of these five run entirely inside your browser. Nothing you paste is uploaded, logged or stored.

Pick a tool

checkYourDomainSec

Point it at a domain and see what the internet already knows: certificates, subdomains, mail spoofing protection, exposed files, third-party scripts, ageing libraries.

  • Graded report in about twenty seconds
  • Passive only, nothing is attacked
  • Every finding says why it matters
Check a domain

Phishing & email analyzer In browser

Paste a suspicious email and read it three ways at once: the SPF, DKIM and DMARC verdict, every link taken apart so a lookalike cannot hide, and the addresses, domains and hashes pulled out as indicators.

  • Display name and Reply-To spoofing checks
  • Every link's real destination, defanged
  • Indicators extracted from the whole message
Analyze an email

Web response analyzer In browser

Everything you read off an HTTPS response, in one place. Grade the security headers and get the lines you are missing, evaluate a Content-Security-Policy or build a strict one, and read an X.509 certificate without an openssl command.

  • HSTS, framing, cookies, CORS and the rest, graded
  • CSP evaluated, with the bypassable hosts named
  • Certificate names, validity, key size and fingerprints
Read a response

Static file analysis In browser

Drop a file to get its MD5, SHA-1, SHA-256 and SHA-512, and to find out what the first bytes say it really is. Nothing is uploaded, so a suspicious file stays yours.

  • Hashed on your machine, not a server
  • Spots an executable wearing a document name
  • Verifies a download against a published hash
Analyse a file

Decoder & token inspector In browser

Paste an encoded blob and the layers come off one at a time: base64, hex, percent encoding, HTML entities, quoted printable, and gzip or zlib underneath any of them.

  • Shows the route, not just the result
  • Decompresses with the browser's own gzip
  • Says when a string is a hash, not a payload
Unwrap something

Why these are free

The phishing triage walkthrough uses four of these in order, the DMARC guide uses the records tool, and the policy guide uses the evaluator. If you are not sure where to start, start there.

We build them because we need them. Putting them here costs us almost nothing and it means the first thing you see from OverWatch Labs is work, not a sales page. If a tool turns up something you would rather talk through, the contact page is one click away, and if it does not, keep the tool.

Beyond the tools

A tool finds the obvious. A person finds the rest.

Web application testing

Manual testing of the logic a scanner cannot reason about: access control between accounts, workflow abuse, and the chains that turn a low finding into a breach.

Red teaming

Phishing, pretexting and quiet lateral movement against the defences you actually run, measured by what your team detected.

Cloud and infrastructure

Review of the identity, network and storage decisions that decide how far a single compromised credential can travel.

AI agent security

Prompt injection, tool abuse and data exfiltration testing for the agents and assistants now touching your production systems.

Want the full picture?

Tell us what you are running and we will tell you what a proper assessment would cover, and what it would cost.