It reads what is public
Your DNS records, your website's front page and public indexes. Nothing to install, no passwords, no access to hand over.
What we check
The scanner has 49 working checks in six areas, and the free check runs all but three. Each one below says what it looks at, why it matters and how far you can trust the result.
Engine 1.21.0, read 25 September 2026
How the scan works
Your DNS records, your website's front page and public indexes. Nothing to install, no passwords, no access to hand over.
A lookup that times out is recorded as unknown. It is never quietly turned into a pass, so a green result is something we saw.
The score travels with a count of the checks that finished. A scan missing a quarter or more of them is marked Incomplete, not given a word.
The checks
Pick an area. Open any check for what it reads and where its limits are.
Email was built on trust: any server can put your domain in the From line. These checks read the DNS records that let a receiving server tell your real email from a fake, and the ones that keep your mail encrypted on the way. This area carries the most weight in the score, because email impersonation is the most common attack and the place most organisations are weakest.
15 checks · 15 in the free check
Without SPF, or with one that ends softly, a receiving server has no list to check a sender against. Two SPF records cancel each other out.
The TXT records at your domain. One v=spf1 record ending in -all passes, ~all warns, a missing or neutral ending fails, and more than one record fails.
None once the DNS lookup completes.
Scored: it can lower your score.
Each service you add to SPF uses lookups. Go past ten and receivers stop reading your SPF at all, so a record that looks fine on paper protects nothing.
The DNS lookups your SPF record triggers (the limit is 10) and the ones that resolve to nothing (the limit is 2).
The count of empty lookups is a floor, so it never over-reports.
Scored: it can lower your score.
DKIM is the tamper-proof signature on your email. Without it, forwarded mail fails DMARC and your policy can never safely reach reject.
The common DKIM selector names in DNS. On Microsoft 365 the names are known, so a miss is a real fail. Elsewhere a miss is reported as information.
A custom selector name cannot be guessed from outside, so we say so instead of failing you.
Scored: it can lower your score.
DMARC at none only watches. Until it is set to quarantine or reject, anyone can send email that appears to come from you. It also caps your score: a domain that can be impersonated cannot score above 69, quarantine cannot score above 89.
The TXT record at _dmarc.yourdomain: the policy, the subdomain policy, and the test-mode tag from the 2026 standard.
None once the DNS lookup completes.
Scored: it can lower your score.
Without MTA-STS, someone on the path can strip the encryption from mail on its way to you, and neither side is told.
The TXT record at _mta-sts.yourdomain.
Presence only. Whether the policy is switched on is check 12.
Scored: it can lower your score.
If a server cannot deliver to you securely, TLS reporting is how you find out. Without it, those failures are silent.
The TXT record at _smtp._tls.yourdomain.
Presence only.
Scored: it can lower your score.
BIMI shows your logo in inboxes that support it. It only works once DMARC is enforced, so it is a reward for doing the rest.
The TXT record at default._bimi.yourdomain.
Presence only. Gmail and Apple Mail also need a mark certificate.
Advice: shown with a recommendation. It never lowers your score.
Every other record here is only as trustworthy as the DNS that serves it. A broken DNSSEC chain can make your whole domain unreachable.
The DS record at your parent zone, and whether a validating resolver confirms a real answer. Signed and valid passes, signed but broken fails, unsigned is information.
Reports unknown when validation cannot complete.
Scored: it can lower your score.
A short key can be cracked, and a cracked key signs fakes that pass every check.
The keys found on the common selectors. RSA under 1,024 bits fails, under 2,048 warns, 2,048 or Ed25519 passes.
Only sizes the keys it can see, so a custom selector may not be graded.
Scored: it can lower your score.
The reports are how you learn who is sending as you. A policy with no reporting address is flying blind.
The rua and ruf addresses in your DMARC record, and the permission record an outside destination must publish to receive them.
A receiver can still choose not to send reports, which nothing outside can see.
Scored: it can lower your score.
A record ending +all approves the whole internet. An include that points at a lapsed domain can be re-registered by a stranger, who then sends as you with your blessing.
The ending of the record, and whether each include and redirect still publishes an SPF record.
A dangling include is a risk, not proof that anyone has claimed it.
Scored: it can lower your score.
It is common to publish MTA-STS in testing mode and forget to switch it on.
The policy file itself, fetched from mta-sts.yourdomain. Enforce passes; testing or none warns.
Needs the policy host to answer at scan time.
Scored: it can lower your score.
Many receivers mark down or refuse mail from a server whose name and address do not match in both directions.
For each mail server address: the reverse record, and whether that name resolves back to the same address.
Reads your inbound mail servers. A provider that sends from a separate pool is a small blind spot.
Scored: it can lower your score.
With one mail server and no backup, an outage means bounced email rather than delayed email.
How many mail servers your MX records name, and how many providers they belong to.
A resilience readout, not a security failing.
Advice: shown with a recommendation. It never lowers your score.
A listed mail server has its email refused. It is worth knowing, and worth confirming yourself.
The Spamhaus blocklist, for each mail server address.
Blocklists refuse questions from cloud networks like ours, so we never let this one change your score. Posture Monitoring watches it with a dedicated key.
Advice: shown with a recommendation. It never lowers your score.
These checks read your website's front page and the encrypted connection to it: the certificate, the versions of TLS it accepts, and the security headers that browsers rely on. They look at the landing page, not pages behind a login.
15 checks · 15 in the free check
TLS 1.0 and 1.1 have known weaknesses and browsers have dropped them. A site that still accepts them can be pushed down to them.
Real handshakes with your web server: the versions and ciphers it accepts, including a direct try of TLS 1.0 and 1.1.
A clean pass is only given when every handshake completed.
Scored: it can lower your score.
An expired or untrusted certificate puts a warning in front of every visitor.
The live certificate chain and its expiry date. Untrusted or expired fails; under 14 days left warns.
None.
Scored: it can lower your score.
Without HSTS, a visitor's first request can be intercepted before it is ever encrypted.
The Strict-Transport-Security header and its lifetime, plus the browsers' preload list.
The preload list is a dated copy, so a very recent addition can be missed. It never gives a false pass.
Scored: it can lower your score.
A site that answers on plain HTTP hands an attacker on the same network the whole conversation.
How your server answers a plain http:// request: a redirect to HTTPS passes, content served in the clear warns.
None.
Scored: it can lower your score.
A good policy is the strongest defence against injected scripts. A policy full of exceptions is a rulebook nobody follows.
The Content-Security-Policy header: unsafe-inline, unsafe-eval, wildcards and a missing default-src are flagged.
Grades the shape of the policy on the landing page. It does not prove an attack would work.
Scored: it can lower your score.
A session cookie without Secure, HttpOnly and SameSite can be read or sent where it should not be.
Each cookie the landing page sets, and its three flags.
Only sees cookies set before login.
Scored: it can lower your score.
A version number tells an attacker exactly which known exploits to try.
The Server and X-Powered-By headers. Out-of-date software fails; a bare version number warns.
"Out of date" is only as current as the engine's last update.
Scored: it can lower your score.
One insecure script on a secure page undoes the security of the whole page.
The landing page's HTML, for scripts, frames, images and stylesheets loaded over http://.
Cannot see what a page adds later with JavaScript.
Scored: it can lower your score.
Without it, an attacker can lay your page invisibly over theirs and borrow your visitor's clicks.
The X-Frame-Options header, or frame-ancestors in your Content-Security-Policy. Either one passes.
None.
Scored: it can lower your score.
A browser that guesses can be tricked into running a file as code.
The X-Content-Type-Options: nosniff header.
None.
Scored: it can lower your score.
Web addresses can carry names, references and tokens. This header limits what travels with a click.
The Referrer-Policy header.
Presence only.
Advice: shown with a recommendation. It never lowers your score.
A feature that is switched off cannot be abused by an injected script.
The Permissions-Policy header.
Presence only.
Advice: shown with a recommendation. It never lowers your score.
Without CAA, any certificate authority in the world can issue a certificate in your name.
The CAA records in your DNS, and whether they carry an issue tag.
None.
Scored: it can lower your score.
A hardened website with a weak mail server is still a weak front door.
Handshakes on four ports: 443, 465, 587 and 993. An old protocol, a weak cipher or a SHA-1 certificate on any of them fails.
Grades the ports that answer. A port that is not exposed is not graded.
Scored: it can lower your score.
One wrong cross-origin setting lets any website read your pages as the signed-in visitor.
The landing page's cross-origin (CORS) behaviour, its allowed HTTP methods, and scripts loaded without a tamper check.
Landing page only. A method probe that cannot finish is reported as unknown.
Scored: it can lower your score.
Your domain is the root of your website and your email. These checks look at how it is registered and served: whether it is close to expiring, whether it can be moved without your say-so, and whether forgotten subdomains are open to a stranger.
8 checks · 5 in the free check
Whoever claims the abandoned service controls a page, and a login form, on your own domain.
Your hostnames from public certificate logs, and whether any points at a third-party service that can be claimed.
Deliberately cautious: only a target that can be shown to be claimable fails. The rest are a warning to check by hand.
Scored: it can lower your score.
A wildcard widens what an attacker can use and masks the typos and leftovers you would otherwise notice.
One lookup of a random name under your domain.
A risk in how the domain is set up, not a proven hole.
Scored: it can lower your score.
A lapsed domain can be bought by anyone, along with every email sent to it.
The registry's expiry date. Inside 30 days fails and inside 90 warns. A domain held five years or more and locked at its registrar warns rather than fails in its last 30 days.
Reports unknown for the few domain endings whose registry does not publish the date.
Scored: it can lower your score.
If your registrar account is ever broken into, the lock is what stops the domain leaving.
The registry's status flags for your domain.
Needs the registry to publish its records.
Scored: it can lower your score.
When someone finds a problem, this is how they find you before they find a journalist.
The file at /.well-known/security.txt.
Reported as unknown when the site does not answer.
Advice: shown with a recommendation. It never lowers your score.
If every name server is on one network and that network fails, your website and email vanish together.
Your name servers and the networks they sit on. Fewer than two, or all on one network, warns.
Reports unknown when too few name servers can be placed.
Scored: it can lower your score.
Naming habits tell an attacker where to look next. Knowing yours tells you what they can guess.
Past hostnames from public certificate logs.
Description, not a verdict.
Context: background only. It is never graded.
Attackers register domains that look almost like yours, and work out how your staff email addresses are formed. These checks show what a stranger can find out, and whether a look-alike domain is already set up to send email.
4 checks · 4 in the free check
It tells us where your DKIM keys should be and which hardening advice applies to you.
Microsoft's own public sign-in discovery pages.
Background only.
Context: background only. It is never graded.
A look-alike with email switched on is a phishing campaign waiting for a send button. One you registered yourself is good practice.
Up to 30 likely variants of your name: which are registered, which can send email, and who owns them where the registry says.
Most registries hide the owner, so many land as "ownership unknown, check". An unusual spelling may not be generated.
Scored: it can lower your score.
A second pass catches look-alikes the first did not think of.
A second search for look-alike domains that can send email.
Never scored, so the same domain is not counted twice.
Context: background only. It is never graded.
Once the pattern is known, every name on your website becomes an address to target.
The likely address pattern, marked as seen or assumed.
A best guess when no real address has been seen.
Context: background only. It is never graded.
Some services publish a searchable index of what every internet address exposes. These checks read that index for your addresses. Nothing is sent to your systems; we read a public catalogue.
3 checks · 3 in the free check
Remote access, databases and admin pages are the first things an attacker looks for.
A public internet index, for your addresses: open ports, and the vulnerabilities it lists against them. Addresses belonging to a content network in front of you are left out.
Open ports are observed. The vulnerability list is the index's inference from version numbers, so it weighs far less and the finding says to confirm it.
Scored: it can lower your score.
A flood aimed at an unshielded server takes the site down with it.
Whether your public addresses sit behind a known scrubbing or content network.
Spotting a shield is reliable. Proving the server behind it can still be reached is harder, so that is a warning.
Scored: it can lower your score.
It turns a technical result into the controls a framework asks about, and names the ones an outside scan cannot assess.
The other checks' results, mapped to common frameworks.
A mapping, not a measurement, and not a certification.
Context: background only. It is never graded.
Most websites load code from other companies. These checks come from a single read of your home page: old libraries with known holes, code loaded without a tamper check, and the third parties and trackers present.
4 checks · 4 in the free check
An old library with a published hole is a well-marked way in.
The version in each script's file name, against a short list of well-known libraries with published vulnerabilities.
A short, high-confidence list. On a site that builds its pages in the browser, it says so and reports unknown.
Scored: it can lower your score.
If a supplier's server is compromised, an integrity check is what stops their altered file running on your site.
The third-party scripts and stylesheets on your home page, and how many carry an integrity hash.
Home page as served.
Scored: it can lower your score.
Every outside script is code you do not control, running with your visitors' trust.
The outside hosts your home page loads code from.
An inventory, never graded.
Context: background only. It is never graded.
Each tracker is something your cookie banner and privacy notice must account for.
Known tracking and analytics scripts on your home page.
Listed only when the site has them.
Context: background only. It is never graded.
How the score works
Every domain starts at 100 and loses points for what the scored checks find. Checks marked advice or context never lower it.
DMARC sets a ceiling. A domain that can still be impersonated cannot score above 69, and one at quarantine cannot score above 89. Only reject can reach Excellent.
| Score | Word | What it means |
|---|---|---|
| 90 to 100 | Excellent | Little for an attacker to work with. |
| 75 to 89 | Good | Sound, with gaps worth closing. |
| 60 to 74 | Fair | Real weaknesses an attacker would find. |
| 40 to 59 | Weak | Several serious gaps. |
| 0 to 39 | Poor | Open to impersonation and more. |
What this scan is not
Subdomain takeover, hidden hostnames and naming history read public certificate logs, a shared source with a strict limit. They run on a customer's own verified domains, not on the free check.
Leaked passwords, infostealer logs, leaked secrets, document metadata and a search for unknown servers have no data source connected. They report nothing, and we do not claim them.
Nothing here tries a password, probes a port or attempts a way in. Anything intrusive needs your written permission and is a separate piece of work.
About 30 seconds. No account. Nothing to install.