What we check

Every check, explained.

The scanner has 49 working checks in six areas, and the free check runs all but three. Each one below says what it looks at, why it matters and how far you can trust the result.

Engine 1.21.0, read 25 September 2026

How the scan works

It looks. It never pokes.

It reads what is public

Your DNS records, your website's front page and public indexes. Nothing to install, no passwords, no access to hand over.

Unknown is never a pass

A lookup that times out is recorded as unknown. It is never quietly turned into a pass, so a green result is something we saw.

Every score says how complete it is

The score travels with a count of the checks that finished. A scan missing a quarter or more of them is marked Incomplete, not given a word.

The checks

Six areas. 49 checks.

Pick an area. Open any check for what it reads and where its limits are.

Can someone send email as you?

Email was built on trust: any server can put your domain in the From line. These checks read the DNS records that let a receiving server tell your real email from a fake, and the ones that keep your mail encrypted on the way. This area carries the most weight in the score, because email impersonation is the most common attack and the place most organisations are weakest.

15 checks · 15 in the free check

01SPF record
The list of servers allowed to send email as you: that it exists, that there is only one, and that it tells receivers to refuse everyone else.
Free checkScoredReliability: Definitive

Why it matters

Without SPF, or with one that ends softly, a receiving server has no list to check a sender against. Two SPF records cancel each other out.

What it reads

The TXT records at your domain. One v=spf1 record ending in -all passes, ~all warns, a missing or neutral ending fails, and more than one record fails.

Where its limits are

None once the DNS lookup completes.

How it counts

Scored: it can lower your score.

02SPF lookup limit
SPF silently stops working past ten DNS lookups. This catches a record that has gone over.
Free checkScoredReliability: Definitive

Why it matters

Each service you add to SPF uses lookups. Go past ten and receivers stop reading your SPF at all, so a record that looks fine on paper protects nothing.

What it reads

The DNS lookups your SPF record triggers (the limit is 10) and the ones that resolve to nothing (the limit is 2).

Where its limits are

The count of empty lookups is a floor, so it never over-reports.

How it counts

Scored: it can lower your score.

03DKIM presence
Looks for your signing key where it is usually published, and says "could not confirm" rather than "missing" when it cannot be sure.
Free checkScoredReliability: High

Why it matters

DKIM is the tamper-proof signature on your email. Without it, forwarded mail fails DMARC and your policy can never safely reach reject.

What it reads

The common DKIM selector names in DNS. On Microsoft 365 the names are known, so a miss is a real fail. Elsewhere a miss is reported as information.

Where its limits are

A custom selector name cannot be guessed from outside, so we say so instead of failing you.

How it counts

Scored: it can lower your score.

04DMARC policy
The master switch: what inboxes do with mail that fails, and whether subdomains are covered. The most important email check.
Free checkScoredReliability: Definitive

Why it matters

DMARC at none only watches. Until it is set to quarantine or reject, anyone can send email that appears to come from you. It also caps your score: a domain that can be impersonated cannot score above 69, quarantine cannot score above 89.

What it reads

The TXT record at _dmarc.yourdomain: the policy, the subdomain policy, and the test-mode tag from the 2026 standard.

Where its limits are

None once the DNS lookup completes.

How it counts

Scored: it can lower your score.

05MTA-STS record
Whether you have told other mail servers to encrypt mail they deliver to you.
Free checkScoredReliability: Definitive

Why it matters

Without MTA-STS, someone on the path can strip the encryption from mail on its way to you, and neither side is told.

What it reads

The TXT record at _mta-sts.yourdomain.

Where its limits are

Presence only. Whether the policy is switched on is check 12.

How it counts

Scored: it can lower your score.

06TLS reporting
Whether you are told when encrypted delivery to you fails.
Free checkScoredReliability: Definitive

Why it matters

If a server cannot deliver to you securely, TLS reporting is how you find out. Without it, those failures are silent.

What it reads

The TXT record at _smtp._tls.yourdomain.

Where its limits are

Presence only.

How it counts

Scored: it can lower your score.

07BIMI
Whether your logo is set up to appear beside your emails. A nice-to-have, never a failing.
Free checkAdviceReliability: Definitive

Why it matters

BIMI shows your logo in inboxes that support it. It only works once DMARC is enforced, so it is a reward for doing the rest.

What it reads

The TXT record at default._bimi.yourdomain.

Where its limits are

Presence only. Gmail and Apple Mail also need a mark certificate.

How it counts

Advice: shown with a recommendation. It never lowers your score.

08DNSSEC
A seal that stops your DNS answers being forged. A broken seal counts as worse than none.
Free checkScoredReliability: Definitive

Why it matters

Every other record here is only as trustworthy as the DNS that serves it. A broken DNSSEC chain can make your whole domain unreachable.

What it reads

The DS record at your parent zone, and whether a validating resolver confirms a real answer. Signed and valid passes, signed but broken fails, unsigned is information.

Where its limits are

Reports unknown when validation cannot complete.

How it counts

Scored: it can lower your score.

09DKIM key strength
Whether your signing keys are long enough that nobody can forge them.
Free checkScoredReliability: High

Why it matters

A short key can be cracked, and a cracked key signs fakes that pass every check.

What it reads

The keys found on the common selectors. RSA under 1,024 bits fails, under 2,048 warns, 2,048 or Ed25519 passes.

Where its limits are

Only sizes the keys it can see, so a custom selector may not be graded.

How it counts

Scored: it can lower your score.

10DMARC reporting
Whether DMARC's daily reports reach a mailbox someone actually reads.
Free checkScoredReliability: High

Why it matters

The reports are how you learn who is sending as you. A policy with no reporting address is flying blind.

What it reads

The rua and ruf addresses in your DMARC record, and the permission record an outside destination must publish to receive them.

Where its limits are

A receiver can still choose not to send reports, which nothing outside can see.

How it counts

Scored: it can lower your score.

11SPF hygiene
An SPF record that lets anyone send, or still points at a supplier you left.
Free checkScoredReliability: High

Why it matters

A record ending +all approves the whole internet. An include that points at a lapsed domain can be re-registered by a stranger, who then sends as you with your blessing.

What it reads

The ending of the record, and whether each include and redirect still publishes an SPF record.

Where its limits are

A dangling include is a risk, not proof that anyone has claimed it.

How it counts

Scored: it can lower your score.

12MTA-STS mode
A policy left in testing mode: it looks present and protects nothing.
Free checkScoredReliability: High

Why it matters

It is common to publish MTA-STS in testing mode and forget to switch it on.

What it reads

The policy file itself, fetched from mta-sts.yourdomain. Enforce passes; testing or none warns.

Where its limits are

Needs the policy host to answer at scan time.

How it counts

Scored: it can lower your score.

13Reverse DNS
Whether your mail servers have the reverse DNS receivers expect. Without it, mail gets marked down.
Free checkScoredReliability: High

Why it matters

Many receivers mark down or refuse mail from a server whose name and address do not match in both directions.

What it reads

For each mail server address: the reverse record, and whether that name resolves back to the same address.

Where its limits are

Reads your inbound mail servers. A provider that sends from a separate pool is a small blind spot.

How it counts

Scored: it can lower your score.

14Backup mail server
Whether mail waits instead of bouncing when your one mail server is down.
Free checkAdviceReliability: High

Why it matters

With one mail server and no backup, an outage means bounced email rather than delayed email.

What it reads

How many mail servers your MX records name, and how many providers they belong to.

Where its limits are

A resilience readout, not a security failing.

How it counts

Advice: shown with a recommendation. It never lowers your score.

15Mail server reputation
Whether your mail servers sit on a spam blocklist. Shown to check by hand, never scored.
Free checkAdviceReliability: Indicative

Why it matters

A listed mail server has its email refused. It is worth knowing, and worth confirming yourself.

What it reads

The Spamhaus blocklist, for each mail server address.

Where its limits are

Blocklists refuse questions from cloud networks like ours, so we never let this one change your score. Posture Monitoring watches it with a dedicated key.

How it counts

Advice: shown with a recommendation. It never lowers your score.

Is your website set up safely?

These checks read your website's front page and the encrypted connection to it: the certificate, the versions of TLS it accepts, and the security headers that browsers rely on. They look at the landing page, not pages behind a login.

15 checks · 15 in the free check

16TLS versions
Your site uses modern encryption, with the old broken versions switched off.
Free checkScoredReliability: Definitive

Why it matters

TLS 1.0 and 1.1 have known weaknesses and browsers have dropped them. A site that still accepts them can be pushed down to them.

What it reads

Real handshakes with your web server: the versions and ciphers it accepts, including a direct try of TLS 1.0 and 1.1.

Where its limits are

A clean pass is only given when every handshake completed.

How it counts

Scored: it can lower your score.

17Certificate
Your HTTPS certificate is genuine, trusted and not about to expire.
Free checkScoredReliability: Definitive

Why it matters

An expired or untrusted certificate puts a warning in front of every visitor.

What it reads

The live certificate chain and its expiry date. Untrusted or expired fails; under 14 days left warns.

Where its limits are

None.

How it counts

Scored: it can lower your score.

18HSTS
Browsers are told always to use the secure version of your site, for long enough to matter.
Free checkScoredReliability: High

Why it matters

Without HSTS, a visitor's first request can be intercepted before it is ever encrypted.

What it reads

The Strict-Transport-Security header and its lifetime, plus the browsers' preload list.

Where its limits are

The preload list is a dated copy, so a very recent addition can be missed. It never gives a false pass.

How it counts

Scored: it can lower your score.

19HTTPS redirect
Typing your address without https still lands on the secure site.
Free checkScoredReliability: Definitive

Why it matters

A site that answers on plain HTTP hands an attacker on the same network the whole conversation.

What it reads

How your server answers a plain http:// request: a redirect to HTTPS passes, content served in the clear warns.

Where its limits are

None.

How it counts

Scored: it can lower your score.

20Content-Security-Policy
A rulebook for what code may run on your pages, graded for obvious holes.
Free checkScoredReliability: High

Why it matters

A good policy is the strongest defence against injected scripts. A policy full of exceptions is a rulebook nobody follows.

What it reads

The Content-Security-Policy header: unsafe-inline, unsafe-eval, wildcards and a missing default-src are flagged.

Where its limits are

Grades the shape of the policy on the landing page. It does not prove an attack would work.

How it counts

Scored: it can lower your score.

21Cookies
Your cookies carry the flags that stop them being stolen or misused.
Free checkScoredReliability: High

Why it matters

A session cookie without Secure, HttpOnly and SameSite can be read or sent where it should not be.

What it reads

Each cookie the landing page sets, and its three flags.

Where its limits are

Only sees cookies set before login.

How it counts

Scored: it can lower your score.

22Server banner
Whether your server announces its software and version: a shopping list for attackers.
Free checkScoredReliability: High

Why it matters

A version number tells an attacker exactly which known exploits to try.

What it reads

The Server and X-Powered-By headers. Out-of-date software fails; a bare version number warns.

Where its limits are

"Out of date" is only as current as the engine's last update.

How it counts

Scored: it can lower your score.

23Mixed content
A secure page loading pieces over an insecure connection.
Free checkScoredReliability: High

Why it matters

One insecure script on a secure page undoes the security of the whole page.

What it reads

The landing page's HTML, for scripts, frames, images and stylesheets loaded over http://.

Where its limits are

Cannot see what a page adds later with JavaScript.

How it counts

Scored: it can lower your score.

24Clickjacking
Your site cannot be hidden inside a malicious page to trick people into clicking.
Free checkScoredReliability: Definitive

Why it matters

Without it, an attacker can lay your page invisibly over theirs and borrow your visitor's clicks.

What it reads

The X-Frame-Options header, or frame-ancestors in your Content-Security-Policy. Either one passes.

Where its limits are

None.

How it counts

Scored: it can lower your score.

25MIME sniffing
A one-line header that stops browsers mis-guessing file types.
Free checkScoredReliability: Definitive

Why it matters

A browser that guesses can be tricked into running a file as code.

What it reads

The X-Content-Type-Options: nosniff header.

Where its limits are

None.

How it counts

Scored: it can lower your score.

26Referrer-Policy
How much of your web addresses leak to the sites your visitors click through to.
Free checkAdviceReliability: Definitive

Why it matters

Web addresses can carry names, references and tokens. This header limits what travels with a click.

What it reads

The Referrer-Policy header.

Where its limits are

Presence only.

How it counts

Advice: shown with a recommendation. It never lowers your score.

27Permissions-Policy
Switching off browser features you never use, such as the camera and microphone.
Free checkAdviceReliability: Definitive

Why it matters

A feature that is switched off cannot be abused by an injected script.

What it reads

The Permissions-Policy header.

Where its limits are

Presence only.

How it counts

Advice: shown with a recommendation. It never lowers your score.

28CAA records
Which companies may issue certificates for your domain.
Free checkScoredReliability: Definitive

Why it matters

Without CAA, any certificate authority in the world can issue a certificate in your name.

What it reads

The CAA records in your DNS, and whether they carry an issue tag.

Where its limits are

None.

How it counts

Scored: it can lower your score.

29TLS on mail ports
The same encryption scrutiny for your mail servers as for your website.
Free checkScoredReliability: High

Why it matters

A hardened website with a weak mail server is still a weak front door.

What it reads

Handshakes on four ports: 443, 465, 587 and 993. An old protocol, a weak cipher or a SHA-1 certificate on any of them fails.

Where its limits are

Grades the ports that answer. A port that is not exposed is not graded.

How it counts

Scored: it can lower your score.

30App-layer headers
A deeper web setting that could let another site read your users' data.
Free checkScoredReliability: High

Why it matters

One wrong cross-origin setting lets any website read your pages as the signed-in visitor.

What it reads

The landing page's cross-origin (CORS) behaviour, its allowed HTTP methods, and scripts loaded without a tamper check.

Where its limits are

Landing page only. A method probe that cannot finish is reported as unknown.

How it counts

Scored: it can lower your score.

Could you lose the domain, or part of it?

Your domain is the root of your website and your email. These checks look at how it is registered and served: whether it is close to expiring, whether it can be moved without your say-so, and whether forgotten subdomains are open to a stranger.

8 checks · 5 in the free check

31Subdomain takeover
A forgotten subdomain still pointing at a cloud service a stranger could sign up for and take over.
Customer scanScoredReliability: Moderate

Why it matters

Whoever claims the abandoned service controls a page, and a login form, on your own domain.

What it reads

Your hostnames from public certificate logs, and whether any points at a third-party service that can be claimed.

Where its limits are

Deliberately cautious: only a target that can be shown to be claimable fails. The rest are a warning to check by hand.

How it counts

Scored: it can lower your score.

32Hidden hostnames
Forgotten test and old systems revealed by public certificate logs.
Customer scanAdviceReliability: Moderate

Why it matters

Every certificate ever issued for you is on public record. Attackers read that list to find the systems you forgot.

What it reads

Public certificate logs, for hostnames that look forgotten or unexpected.

Where its limits are

The hostnames are real. "Looks forgotten" is a judgement, so treat it as a prompt to look.

How it counts

Advice: shown with a recommendation. It never lowers your score.

33Wildcard DNS
Any made-up subdomain resolving to something, which hides mistakes.
Free checkScoredReliability: High

Why it matters

A wildcard widens what an attacker can use and masks the typos and leftovers you would otherwise notice.

What it reads

One lookup of a random name under your domain.

Where its limits are

A risk in how the domain is set up, not a proven hole.

How it counts

Scored: it can lower your score.

34Domain expiry
How close your domain is to lapsing, which would take your website and email with it.
Free checkScoredReliability: Definitive

Why it matters

A lapsed domain can be bought by anyone, along with every email sent to it.

What it reads

The registry's expiry date. Inside 30 days fails and inside 90 warns. A domain held five years or more and locked at its registrar warns rather than fails in its last 30 days.

Where its limits are

Reports unknown for the few domain endings whose registry does not publish the date.

How it counts

Scored: it can lower your score.

35Transfer lock
Your domain cannot be moved to another registrar without your say-so.
Free checkScoredReliability: Definitive

Why it matters

If your registrar account is ever broken into, the lock is what stops the domain leaving.

What it reads

The registry's status flags for your domain.

Where its limits are

Needs the registry to publish its records.

How it counts

Scored: it can lower your score.

36security.txt
A file telling researchers how to report a vulnerability to you.
Free checkAdviceReliability: High

Why it matters

When someone finds a problem, this is how they find you before they find a journalist.

What it reads

The file at /.well-known/security.txt.

Where its limits are

Reported as unknown when the site does not answer.

How it counts

Advice: shown with a recommendation. It never lowers your score.

37Name server backup
Your DNS does not all sit in one place whose outage would take your domain dark.
Free checkScoredReliability: High

Why it matters

If every name server is on one network and that network fails, your website and email vanish together.

What it reads

Your name servers and the networks they sit on. Fewer than two, or all on one network, warns.

Where its limits are

Reports unknown when too few name servers can be placed.

How it counts

Scored: it can lower your score.

38Naming history
How you tend to name your systems, as context.
Customer scanContextReliability: Indicative

Why it matters

Naming habits tell an attacker where to look next. Knowing yours tells you what they can guess.

What it reads

Past hostnames from public certificate logs.

Where its limits are

Description, not a verdict.

How it counts

Context: background only. It is never graded.

Who could pass themselves off as you?

Attackers register domains that look almost like yours, and work out how your staff email addresses are formed. These checks show what a stranger can find out, and whether a look-alike domain is already set up to send email.

4 checks · 4 in the free check

39Microsoft 365
Whether you run on Microsoft 365, as context for the rest.
Free checkContextReliability: Definitive

Why it matters

It tells us where your DKIM keys should be and which hardening advice applies to you.

What it reads

Microsoft's own public sign-in discovery pages.

Where its limits are

Background only.

How it counts

Context: background only. It is never graded.

40Look-alike domains
Domains that look almost like yours, and whether a stranger or you owns each one.
Free checkScoredReliability: Moderate

Why it matters

A look-alike with email switched on is a phishing campaign waiting for a send button. One you registered yourself is good practice.

What it reads

Up to 30 likely variants of your name: which are registered, which can send email, and who owns them where the registry says.

Where its limits are

Most registries hide the owner, so many land as "ownership unknown, check". An unusual spelling may not be generated.

How it counts

Scored: it can lower your score.

41Brand abuse
A wider net for impersonation domains, shown as information.
Free checkContextReliability: Moderate

Why it matters

A second pass catches look-alikes the first did not think of.

What it reads

A second search for look-alike domains that can send email.

Where its limits are

Never scored, so the same domain is not counted twice.

How it counts

Context: background only. It is never graded.

42Email format
What a stranger could guess about your staff email addresses.
Free checkContextReliability: Indicative

Why it matters

Once the pattern is known, every name on your website becomes an address to target.

What it reads

The likely address pattern, marked as seen or assumed.

Where its limits are

A best guess when no real address has been seen.

How it counts

Context: background only. It is never graded.

What have you left open to the internet?

Some services publish a searchable index of what every internet address exposes. These checks read that index for your addresses. Nothing is sent to your systems; we read a public catalogue.

3 checks · 3 in the free check

43Exposed services
Risky services open to the internet, read from a public index without touching your systems.
Free checkScoredReliability: Moderate

Why it matters

Remote access, databases and admin pages are the first things an attacker looks for.

What it reads

A public internet index, for your addresses: open ports, and the vulnerabilities it lists against them. Addresses belonging to a content network in front of you are left out.

Where its limits are

Open ports are observed. The vulnerability list is the index's inference from version numbers, so it weighs far less and the finding says to confirm it.

How it counts

Scored: it can lower your score.

44DDoS protection
Whether a shield sits in front of your site, or attackers can hit the server directly.
Free checkScoredReliability: Moderate

Why it matters

A flood aimed at an unshielded server takes the site down with it.

What it reads

Whether your public addresses sit behind a known scrubbing or content network.

Where its limits are

Spotting a shield is reliable. Proving the server behind it can still be reached is harder, so that is a warning.

How it counts

Scored: it can lower your score.

45Compliance mapping
Your results in the language auditors use, honest about what a scan cannot see.
Free checkContextReliability: High

Why it matters

It turns a technical result into the controls a framework asks about, and names the ones an outside scan cannot assess.

What it reads

The other checks' results, mapped to common frameworks.

Where its limits are

A mapping, not a measurement, and not a certification.

How it counts

Context: background only. It is never graded.

Whose code runs on your website?

Most websites load code from other companies. These checks come from a single read of your home page: old libraries with known holes, code loaded without a tamper check, and the third parties and trackers present.

4 checks · 4 in the free check

46Vulnerable JavaScript
Old JavaScript libraries with known holes, loaded on your home page.
Free checkScoredReliability: Moderate

Why it matters

An old library with a published hole is a well-marked way in.

What it reads

The version in each script's file name, against a short list of well-known libraries with published vulnerabilities.

Where its limits are

A short, high-confidence list. On a site that builds its pages in the browser, it says so and reports unknown.

How it counts

Scored: it can lower your score.

47Subresource Integrity
Whether code loaded from other servers is checked against tampering.
Free checkScoredReliability: High

Why it matters

If a supplier's server is compromised, an integrity check is what stops their altered file running on your site.

What it reads

The third-party scripts and stylesheets on your home page, and how many carry an integrity hash.

Where its limits are

Home page as served.

How it counts

Scored: it can lower your score.

48Third-party code
Whose code runs in your visitors' browsers besides yours.
Free checkContextReliability: High

Why it matters

Every outside script is code you do not control, running with your visitors' trust.

What it reads

The outside hosts your home page loads code from.

Where its limits are

An inventory, never graded.

How it counts

Context: background only. It is never graded.

49Trackers
The analytics and tracking tools on your site, which matter for cookie consent.
Free checkContextReliability: High

Why it matters

Each tracker is something your cookie banner and privacy notice must account for.

What it reads

Known tracking and analytics scripts on your home page.

Where its limits are

Listed only when the site has them.

How it counts

Context: background only. It is never graded.

Definitive: reads a published valueHigh: narrow, known blind spotsModerate: confirm before actingIndicative: a pointer, not a verdict

How the score works

One number, five words.

Every domain starts at 100 and loses points for what the scored checks find. Checks marked advice or context never lower it.

DMARC sets a ceiling. A domain that can still be impersonated cannot score above 69, and one at quarantine cannot score above 89. Only reject can reach Excellent.

What each score means
ScoreWordWhat it means
90 to 100ExcellentLittle for an attacker to work with.
75 to 89GoodSound, with gaps worth closing.
60 to 74FairReal weaknesses an attacker would find.
40 to 59WeakSeveral serious gaps.
0 to 39PoorOpen to impersonation and more.

What this scan is not

The limits, stated plainly.

Three checks need an account

Subdomain takeover, hidden hostnames and naming history read public certificate logs, a shared source with a strict limit. They run on a customer's own verified domains, not on the free check.

Five checks are built, not switched on

Leaked passwords, infostealer logs, leaked secrets, document metadata and a search for unknown servers have no data source connected. They report nothing, and we do not claim them.

It is not a penetration test

Nothing here tries a password, probes a port or attempts a way in. Anything intrusive needs your written permission and is a separate piece of work.

See how your domain does.

About 30 seconds. No account. Nothing to install.