Free tool Passive check

See what the internet sees of your domain.

HTTPS, security headers, email spoofing protection, DNS hardening and publicly logged subdomains, checked in seconds. Every issue comes with the evidence and a fix you can copy.

Passive checks only. We load your homepage once and read public DNS and certificate logs. Results are kept for 10 minutes, then discarded.

What we check

Four areas, all from public information.

Website hardening

Certificate and TLS versions, the HTTP to HTTPS redirect, HSTS, Content-Security-Policy, clickjacking protection, cookie flags, version banners and security.txt.

Email and domain trust

Whether someone can send email that appears to come from you: SPF, DKIM and DMARC, plus MTA-STS and TLS reporting for inbound mail.

DNS configuration

DNSSEC signing, and CAA records that limit which certificate authorities may issue certificates for your domain.

Exposed surface

Subdomains already listed in public Certificate Transparency logs, with non-production and admin names flagged for review.

What we never do.

  • Scan ports or probe for hidden files and paths.
  • Log in, submit forms or test for exploitable bugs.
  • Publish or index results. Report links are not public pages.
  • Ask for an email address to show you the report.

Anyone can type any domain, so the tool only reads what a browser or a DNS lookup already sees. Testing a system for exploitable weaknesses needs the owner's authorization, which is what an assessment provides.

How the grade works.

Each area starts at 100. A high-severity issue removes 25 points, medium 10 and low 3. Passes and informational notes cost nothing. The overall score weights website hardening 40%, email 35%, exposed surface 15% and DNS 10%, using only the areas that could be checked.

A
90+
B
80+
C
65+
D
50+
F
below 50

A good grade is a good sign, not a certificate. This check cannot see application logic, access control, internal networks or source code. Read how access-control flaws hide from scanners.