What this tool checks
- SSL certificate validity and days remaining
- HTTP to HTTPS redirect
- TLS 1.3 support and legacy TLS versions
- HSTS, CSP, X-Frame-Options and X-Content-Type-Options
- SPF and DMARC policy
- DNSSEC and CAA
- Server, CDN and software technologies
How to use it
- 01
Enter a domain name (example.com).
- 02
Press Scan; checks run in parallel and usually take a few seconds.
- 03
Start with the failed checks under the score — each row explains why it matters.
Technical details
How the score works
Encryption (certificate, redirect, TLS versions) carries the most weight, followed by security headers, email authentication and DNS settings. The score measures externally verifiable controls, not vulnerabilities inside the application.
Passive and safe
The scanner only reads public information: the homepage response, the TLS handshake and DNS records. No login attempts, exploits or heavy request volumes.
Limits of a score
A high score is a good start but not a substitute for a penetration test. Authentication flaws, business logic bugs and internal network risks only surface in expert testing.
Frequently asked questions
Does a score of 100 mean my site is secure?
It means the externally visible baseline is in good shape. Application vulnerabilities, weak passwords or broken authorization don't show up in this scan — those need a web application penetration test.
What do I see when scanning a site behind Cloudflare?
The certificate and headers come from Cloudflare's edge, which is what visitors actually get. Check separately whether your origin server is directly reachable.
Can I scan someone else's domain?
The tool reads only public information that anyone can see. Still, run deeper tests only on systems you are authorized to test.
Can I get a detailed report?
Yes. Use the link on the results screen to request a professional security assessment; our team reviews your external attack surface manually.