First one is on the house!
Enter a website domain and receive a clear overview of publicly visible security exposure.
What the free scan looks at
The connection, and the certificate behind it
We complete a TLS handshake the way a browser would, then read what the server actually presented rather than what it claims to support.
- Certificate expiry, hostname match, and whether the chain is trusted
- Legacy protocol versions still being accepted
- HSTS, and whether plain http quietly serves the site instead of redirecting
Who is allowed to send mail as you
SPF, DMARC and MTA-STS are published in your DNS for anyone to read, and they are the records that decide whether a forged invoice from your domain reaches a customer.
- Whether DMARC exists, and whether its policy actually rejects anything
- SPF that ends in a catch-all, or exceeds the ten-lookup limit
- Whether a domain that accepts mail publishes a transport policy
- acmecorp.com
- www.acmecorp.com
- mail.acmecorp.com
- vpn.acmecorp.com
- staging.acmecorp.com
- old-portal.acmecorp.com
Everything carrying your name
Certificate Transparency is a public append-only log of every certificate issued since 2018. Reading it maps your hostnames without sending a single packet to you, and it routinely surfaces a host nobody has thought about in years.
- Subdomains found in public certificate logs
- Standard files you publish, and directories a server lists to anyone
- Whether a firewall or a content network sits in front of the origin
acmecrp.com
Names built to be misread as yours
A lookalike domain costs a few euros and is the first move in most invoice fraud. We generate the plausible variants of your name and check which ones somebody has already registered.
- Character swaps, insertions and neighbouring keyboard slips
- Which of those registrations can send and receive mail
- The logos and images a convincing copy of your site would reuse
Interested in a pentest?
Discover how AI-backed pentesting gives your organization faster and more thorough insight into vulnerabilities.
Contact us
