Attack Surface Quick Check (Free)
Enter a domain and this tool performs a quick external posture check — HTTPS, browser security headers, security.txt, and email authentication (SPF/DMARC). Results appear on the page; no email required.
How it works
We fetch your site over HTTPS and inspect the response headers, request the standard security.txt location, and query public DNS for SPF and DMARC records. Each passed check contributes to a posture score with the failing items listed.
Limitations
This is a lightweight, best-effort external check, not a vulnerability scan or penetration test. It inspects publicly visible configuration only, may be affected by CDNs or firewalls, and does not test for exploitable vulnerabilities. Use it to prioritise, not as an assurance of security.
Frequently asked questions
Is it free and anonymous?
Yes. The check runs server-side on your domain's public configuration and returns results on the page — no email, no account.
What does it actually test?
HTTPS reachability, browser security headers, the presence of security.txt, and SPF/DMARC email authentication records.
Is a high score a clean bill of health?
No. It reflects only a few externally visible signals. It is not a vulnerability assessment or a guarantee of security.