How exposed is your domain? Find out in 30 seconds.
A passive, non-intrusive check of your email security, website headers and domain hygiene. You get a score and the top five issues to fix.
What we check
- Email spoofing protection — SPF and DMARC policy
- Website security headers — HSTS, CSP, clickjacking, nosniff, Referrer- and Permissions-Policy
- HTTPS — reachable over HTTPS and HTTP redirects to HTTPS
- DNS hygiene — CAA and DNSSEC
- Technology disclosure — server version leaks
- Domain expiry — public registry (RDAP) date
Passive checks only — no port scans, no payloads, no crawling. Rate-limited to prevent abuse.
Your results
All checks
About the free check
Is this scan intrusive?
No. We only read public information — DNS records, the security headers your homepage already sends to every visitor, and public registry (RDAP) data. We do not port-scan, send attack payloads or crawl your site.
Why do you need my email?
So a consultant can follow up with context on the results if you want. We use it only for that purpose, as described in our Privacy Policy.
Why do I need to confirm I am authorised?
Even passive checks should only be run on domains you own or manage. Deeper testing in a full audit additionally requires verified domain ownership and a signed authorisation.
What does the full audit add?
TLS configuration grading, DKIM, reputation and breach-exposure lookups, authenticated testing, and a proper VAPT with a CVSS-scored report and retest.