What we check
The same things an attacker would see
Based exclusively on publicly available information — no intrusion into your systems.
Email security
SPF, DMARC and DKIM — the basics for preventing email spoofing on behalf of your domain.
Certificates & encryption
Validity of your TLS certificate and the supported protocol versions.
Visible assets
Subdomains publicly registered via Certificate Transparency logs.
Web configuration
Security headers and technology information exposed by your servers.
How it works
From domain name to result in three steps
01
Enter your domain
No installation or access required — just your domain name.
02
Passive scan
We only query publicly available sources such as DNS, certificates and HTTP headers.
03
Instant result
Within about 30 seconds you'll see a first snapshot, with the option to receive the full report by email.