Emails in your name
SPF · DKIM · DMARC · MTA-STS
Email and domain settings (SPF, DKIM, DMARC, MTA-STS): whether someone can send an email from your address that looks real to a customer.
Enter a site address — in a minute, you will see what anyone who decides to take a closer look can find out about your domain and what to close first.
Free, no registration, your site keeps working
The check is passive: we look at what is already known about a domain from the internet and don't disturb visitors.
Eight groups — eight answers about what is already known about your business. "All clear here" is also a result, and it goes into the report as a separate list.
SPF · DKIM · DMARC · MTA-STS
Email and domain settings (SPF, DKIM, DMARC, MTA-STS): whether someone can send an email from your address that looks real to a customer.
Certificate · encryption · https · HSTS
Certificate expiry and chain, old encryption versions, redirect to https, HSTS. The browser will show visitors a "site not secure" warning — some people will simply leave.
Headers · CORS · cookie · caching
Security headers, CORS, cookie flags, caching, server version in the response. Because of this, your pages can be embedded in someone else's frame.
Third-party code · libraries · forms
Third-party code on the home page, outdated libraries, scripts without integrity checks, forms that send data to another domain. Visitors will enter their card details on a substituted form themselves.
Admin panels · robots.txt · security.txt
Whether admin panel addresses are reachable from the internet, whether there is a simple username and password login, what is in robots.txt, and whether security.txt is published.
.env · .git · lock files · keys
Service files and configurations (.env, .git), lock files, keys inside scripts, exposed machine learning panels. They usually leak because of an oversight during a website migration.
Similar addresses · subdomains · public addresses
Similar addresses used to deceive customers, subdomains from certificate logs, public email addresses, old page addresses.
Blacklists · registrar · registration expiry
Blacklists, registrar, registration expiry date. If you end up on a blacklist, email will not be delivered; if you let the domain expire, it can be taken away.
Why this matters to you: in our check of 487 small and medium-sized business websites email from the domain could be spoofed in 88% of cases — no DMARC email authentication or working policy.
The free external perimeter check is a look at the main list; the paid check goes deeper. Here is the honest difference, no pressure.
| What we compare | Free external perimeter check, $0 | Paid check: $49 for the first, $5 for the next one |
|---|---|---|
| Domain and email | Basic records: SPF, DKIM, DMARC, MTA-STS, CAA | The same plus email servers: encryption, forwarding, service commands |
| Ports and services | We do not look at ports: we do not connect to them | Key ports, service versions, dangerous internet-facing services |
| CMS and plugins | Only the system type identified from external signals | System, plugin, and theme versions checked against vulnerability databases |
| Service paths and subdomains | Typical paths; subdomains from certificate logs | Path and name enumeration, hidden parameters, API documentation, subdomain takeover |
| Ownership and frequency | Not required; can be run once every 30 days | Code by email; can be run once an hour |
The paid check is not a required next step. If the free report already shows something important, fix it and rest easy. A deeper look is worth it when your website handles payments and customer data.
How our external perimeter check works — on the home page.
For us, boundaries matter more than a nice promise.
Yes. We only check the domain you enter. We do not perform password guessing, do not break forms, and do not gain access to data. Ownership verification is only required for the paid check — a code by email. We do not store raw data or share it with third parties.
No. We do not stress-test the site and do not send thousands of requests. The check asks a small number of normal questions about settings, certificate, and headers — like a single visitor. The site works as usual.
Those are tools: a vulnerability database and a list of findings you need to know how to use. Here you get a ready answer: what is known about the domain, what it could lead to, and what to fix first.
Work through the report by priority: some items you can close yourself in five minutes — a certificate, a domain record, a header. Hand anything more complex to your contractor together with the report. After making changes, run the check again to see what has been closed and what remains.
The check is a starting point: we show what is visible for a domain, and if the result matters, a deeper paid check is available. There are two limits: a free run no more than once every 30 days per domain, and less depth.
Correct. A pentest is when a security specialist manually tries to break into a site: chains findings together, tests them in practice, and gets into business logic. This is long, expensive work, usually done once a year. We show what is known about a domain from the internet and what it could lead to.
Enter your domain and see what is already known about your website. No registration needed. If there are no findings, you know exactly what was checked. If there are findings, you leave with a list: what to fix first and who should handle it.
Check your website for free Need a deeper look — get a paid check