Find security misconfigurations before your customers — or an attacker — do.
Scan any domain you own for missing security headers, SSL/TLS certificate problems, DNS and email-authentication gaps, and insecure redirect or cookie setup. Most scans complete in seconds (up to 60s for slow targets), no account or credit card required.
This is a security misconfiguration scanner, not a penetration test. It reads publicly observable configuration — response headers, certificates, DNS records, cookie flags, redirects and detectable technology — and never attempts exploitation. It does not run CVE or exploit scans, WordPress plugin vulnerability scans, malware scans, or AI-based analysis.
A handful of gaps show up on almost every first scan — an HSTS header that was never added being one of the most common. See what that looks like on the missing HSTS finding page.
Check Your Website Security
Get a detailed security report in seconds. No credit card required.
What the scan actually checks
Four categories, all read from publicly observable configuration. Each links to a dedicated deep-dive if you want the detail behind a single category.
Security Headers
Checks whether the response sends the headers browsers rely on to enforce transport security and stop common injection and clickjacking techniques.
- HTTP Strict Transport Security (HSTS)
- Content-Security-Policy (CSP)
- X-Frame-Options
- X-Content-Type-Options
- Referrer-Policy
- Permissions-Policy
- Deprecated / legacy headers still being served
SSL / TLS
Checks the certificate and negotiated protocol actually presented to a visitor's browser, not just whether HTTPS is present.
- Certificate expiry countdown
- Hostname / SAN match
- Self-signed or untrusted issuer detection
- Weak or deprecated TLS protocol versions
- Certificate chain completeness
DNS & Email Authentication
Checks DNS resolution health and the records that stop your domain from being spoofed in email, plus DNS integrity signals.
- DNS resolution (A/AAAA/CNAME)
- SPF record presence and syntax
- DMARC policy presence
- CAA record presence
- DNSSEC signing presence
Redirects, Cookies & Technology
Checks how the site is actually wired up: whether HTTP forces HTTPS, how cookies are flagged, and what's running underneath.
- HTTP → HTTPS redirect configuration
- Cookie Secure / HttpOnly / SameSite flags
- Technology stack detection (server, CMS, frameworks in use)
How your score is calculated
Every check above rolls into a single numeric score and letter grade, so you can see overall posture at a glance and still drill into exactly what moved it. The full scoring methodology — how categories are weighted and how grade boundaries are set — is documented on its own page.
See the scoring methodologyCheck a single thing instead
Prefer to check just one category? Each of these focuses on a single check with more detail than fits above.
Deep-dive on HSTS, CSP, X-Frame-Options and the rest, header by header.
Certificate expiry, chain, hostname match and protocol strength in detail.
Email-spoofing protection: SPF syntax and DMARC policy explained.
Resolution health and DNS-layer misconfiguration in one view.
Whether your zone is signed and validating correctly.
Which certificate authorities are allowed to issue for your domain.
How the letter grade and numeric score are actually calculated.
Frequently asked questions
Is this a vulnerability scanner or a penetration test?
Neither. It's a security misconfiguration scanner: it reads publicly observable configuration such as response headers, certificates, DNS records and cookie flags. It does not attempt exploitation, and it does not run CVE, exploit, WordPress plugin, or malware scans.
What does the scanner check?
Security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, plus deprecated headers), SSL/TLS (expiry, hostname match, self-signed/weak protocol detection, chain), DNS (resolution, SPF, DMARC, CAA, DNSSEC presence), cookie flags, redirect/HTTPS configuration, and technology detection.
How is the security score calculated?
Each check category contributes to an overall score and letter grade. The full methodology — how categories are weighted and how the grade boundaries are set — is documented on the Website Security Score page.
Do I need an account to scan my site?
No. The scanner above runs without a login or credit card. Creating a free account adds continuous rescans and removes the shared per-IP scan limit.
Can I scan a domain I don't own?
The scanner only reads publicly available information and performs no exploitation, but you must confirm you own or are authorized to assess the target domain before a scan runs.