Automated security check
See what your website exposes. Free.
A non-invasive review of publicly observable signals: security headers, email & DNS records, transport security, and your visible attack surface.
100% passive check. No intrusive exploits sent.
This is an automated security check, not a penetration test. It performs no intrusive testing and does not attempt to exploit anything. Penetration testing happens only after written authorization and an agreed scope.
What we look at
- HTTPS and transport configuration
- Security headers (HSTS, CSP, X-Frame-Options)
- Cookie flags (Secure, HttpOnly)
- Email posture (SPF, DMARC)
- Technology and server exposure
- Common security misconfigurations
What we never do
- Attempt exploitation of your systems
- Send intrusive or destructive payloads
- Test systems you haven't authorized
- Store your assessment results on this site