Free tool · live

Scan your website's security — in seconds.

Enter your domain and get an instant external security grade: TLS and certificate health, email spoofing protection (SPF/DMARC), HTTP security headers, and the version leaks attackers look for. It's passive and non-intrusive — we read only what the public internet already exposes.

Passive, non-intrusive: we read only what any visitor and a DNS lookup already see. Nothing is exploited.

Want the deep scan?

Verify you own the domain and add your origin server IP, and we'll scan the real server behind your CDN — open ports, exposed services and version-level vulnerabilities. Authorized targets only.

Request a deep authorized scan →

Enter your domain and scan — your external security grade and findings appear here.

Free scan (this tool): passive external reconnaissance — the same signals a browser and a DNS lookup already see. No login, no exploitation, safe to run on any domain you operate.

Deep authorized scan: for a full origin-level assessment — open ports, exposed services and version-level vulnerabilities on the real server behind your CDN — we first verify you own the domain, then scan with your authorization. That's a service, not a self-serve tool, precisely because scanning a system you don't own is something we take seriously.