Online website security check

Enter a site address — in a minute, you will see what anyone who decides to take a closer look can find out about your domain and what to close first.

Free, no registration, your site keeps working

The check is passive: we look at what is already known about a domain from the internet and don't disturb visitors.

What we check in these 60 seconds

Eight groups — eight answers about what is already known about your business. "All clear here" is also a result, and it goes into the report as a separate list.

Emails in your name

SPF · DKIM · DMARC · MTA-STS

Email and domain settings (SPF, DKIM, DMARC, MTA-STS): whether someone can send an email from your address that looks real to a customer.

Certificate and encryption

Certificate · encryption · https · HSTS

Certificate expiry and chain, old encryption versions, redirect to https, HSTS. The browser will show visitors a "site not secure" warning — some people will simply leave.

Response headers and cookies

Headers · CORS · cookie · caching

Security headers, CORS, cookie flags, caching, server version in the response. Because of this, your pages can be embedded in someone else's frame.

Pages, forms, and third-party code

Third-party code · libraries · forms

Third-party code on the home page, outdated libraries, scripts without integrity checks, forms that send data to another domain. Visitors will enter their card details on a substituted form themselves.

Login panels and service addresses

Admin panels · robots.txt · security.txt

Whether admin panel addresses are reachable from the internet, whether there is a simple username and password login, what is in robots.txt, and whether security.txt is published.

Exposed files, keys, and AI components

.env · .git · lock files · keys

Service files and configurations (.env, .git), lock files, keys inside scripts, exposed machine learning panels. They usually leak because of an oversight during a website migration.

What is known about you from public sources

Similar addresses · subdomains · public addresses

Similar addresses used to deceive customers, subdomains from certificate logs, public email addresses, old page addresses.

Domain reputation and registration expiry

Blacklists · registrar · registration expiry

Blacklists, registrar, registration expiry date. If you end up on a blacklist, email will not be delivered; if you let the domain expire, it can be taken away.

Why this matters to you: in our check of 487 small and medium-sized business websites email from the domain could be spoofed in 88% of cases — no DMARC email authentication or working policy.

Full list of checks →

How it works

  1. Enter a domain. No registration or proof of ownership is needed: the check only looks at what is already open.
  2. The check takes about a minute. The system makes a small number of ordinary requests to the site, domain, and public directories — like one visitor. It does not guess passwords or test the site's strength.
  3. You get a report. For each finding: what is visible, how it can be used, what it could lead to, and what to close first. Separately, what's in good shape. You can forward the report to your contractor and run the check again after making changes.

How this differs from the paid check

The free external perimeter check is a look at the main list; the paid check goes deeper. Here is the honest difference, no pressure.

What we compare Free external perimeter check, $0 Paid check: $49 for the first, $5 for the next one
Domain and email Basic records: SPF, DKIM, DMARC, MTA-STS, CAA The same plus email servers: encryption, forwarding, service commands
Ports and services We do not look at ports: we do not connect to them Key ports, service versions, dangerous internet-facing services
CMS and plugins Only the system type identified from external signals System, plugin, and theme versions checked against vulnerability databases
Service paths and subdomains Typical paths; subdomains from certificate logs Path and name enumeration, hidden parameters, API documentation, subdomain takeover
Ownership and frequency Not required; can be run once every 30 days Code by email; can be run once an hour

The paid check is not a required next step. If the free report already shows something important, fix it and rest easy. A deeper look is worth it when your website handles payments and customer data.

How our external perimeter check works — on the home page.

What we don't check

For us, boundaries matter more than a nice promise.

  • We don't test the site's strength. This is not a pentest: we don't guess passwords, we don't use what we find, and we don't combine small details into an attack chain.
  • We don't look for errors in code or logic. Prices, orders, the customer area, and access rights are internal and require access to the code.
  • We don't confirm a breach. A sign of unauthorized code is a reason to investigate, not a conclusion: a breach can only be confirmed from the inside.
  • We don't present 'closed' as a problem. A closed panel is normal: these items appear under 'What's in good shape,' not under findings.

FAQ

Is this legal?

Yes. We only check the domain you enter. We do not perform password guessing, do not break forms, and do not gain access to data. Ownership verification is only required for the paid check — a code by email. We do not store raw data or share it with third parties.

Will this put load on my website?

No. We do not stress-test the site and do not send thousands of requests. The check asks a small number of normal questions about settings, certificate, and headers — like a single visitor. The site works as usual.

How is this different from free scanners for security specialists?

Those are tools: a vulnerability database and a list of findings you need to know how to use. Here you get a ready answer: what is known about the domain, what it could lead to, and what to fix first.

What to do with findings?

Work through the report by priority: some items you can close yourself in five minutes — a certificate, a domain record, a header. Hand anything more complex to your contractor together with the report. After making changes, run the check again to see what has been closed and what remains.

Why is it free and what's the catch?

The check is a starting point: we show what is visible for a domain, and if the result matters, a deeper paid check is available. There are two limits: a free run no more than once every 30 days per domain, and less depth.

Is this really not a pentest?

Correct. A pentest is when a security specialist manually tries to break into a site: chains findings together, tests them in practice, and gets into business logic. This is long, expensive work, usually done once a year. We show what is known about a domain from the internet and what it could lead to.

Start with a free check

Enter your domain and see what is already known about your website. No registration needed. If there are no findings, you know exactly what was checked. If there are findings, you leave with a list: what to fix first and who should handle it.

Check your website for free Need a deeper look — get a paid check