- Free
- No account
- 16 checks
- ~20 seconds
Free domain scan.
See what attackers see.
16 checks on what your domain publishes to the internet — email authentication, certificate, DNS records, public reputation.
Report including recommended remediation.
- Passive checks
- Remediation included
How it works
Three steps, no account.
You type a domain. We read what is already public. You get a list you can act on.
Enter your domain
Just the domain — no login, no agent to install. You confirm you’re authorised to check it.
We read public records
DNS, certificate transparency logs, your site’s public response and open abuse feeds. Nothing is scanned or probed.
You get the fix list
16 results, each with the change to make and who owns it — your DNS admin, web host, email admin or registrar.
Read this with your result
What this tells you — and what it doesn’t.
A free external check is worth having and worth being honest about. Three things it cannot see.
01
It looks from the outside only
Your laptops, your backups, your logins, who is watching at 2am — none of that is visible from the public internet. A clean result is a clean front door, not a secure building.
02
Some answers are inconclusive
DKIM keys sit on names that cannot be listed, so we check the common ones and say “not found” rather than “absent”. A lookup that times out is never reported as a missing record.
03
A CDN changes the picture
If you sit behind Cloudflare or similar, several checks describe that service’s settings as much as your own. Useful either way — it is also what your customers see.
A score is a conversation starter, not a certification. Closing these items reduces what an attacker can use. It does not make you compliant, and we won’t tell you it does.
Questions
Before you run it.
Does this touch my systems?
No scanning, no probing, no logging in. We read public DNS records, public certificate transparency logs, open abuse feeds, and your website’s public response — the same requests any browser makes when someone visits you. Port information comes from public internet-wide scan data that already exists, not from us scanning you.
Do you store my result?
No. Running the scan stores nothing against your name.
Can I scan a domain I don’t own?
No. You confirm you’re authorised before the scan runs, and that confirmation is logged with the result. Scanning someone else’s domain without authority is a matter for the Computer Misuse Act, not a convenience feature.
How do I stop you checking my domain?
Email [email protected] with the domain. We add it to a block list, the tool refuses to check it from then on, and we reply to confirm.
What do the 16 checks cover?
Email authentication (SPF, DKIM, DMARC); your certificate and encryption (validity, expiry, HTTP to HTTPS redirect, outdated TLS); website headers (HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, version leaks, security.txt); domain records (CAA, DNSSEC); and reputation and exposure (blocklists, publicly reachable services and logins). We also show the host names published in certificate logs, as a finding rather than a score.
How is the score calculated?
Your score starts at 100 and loses points for each check that fails. Every check carries a fixed weight set by risk, not by how easy it is to measure — a missing DMARC policy costs far more than a missing Referrer-Policy header, so the score moves with what actually matters.
Is my score published anywhere?
No. Your result is yours. We don’t publish it, list it, sell it or share it with anyone, and there is no public directory of scanned domains. Nothing is even stored against your name.
Will a good score make me compliant?
No. This looks at the outside of your organisation only, and compliance frameworks look at how you run it. It is a useful starting point for a Cyber Essentials conversation, nothing more.
What if something needs fixing and we have no IT team?
Most of these are a single record, file or toggle, and every result names who owns it so you can forward the report to your IT provider as-is. If you’d rather we walked through it with you, the enquiry form below reaches our Singapore team.
Resources
When you’re ready to go further.
The domain scan looks at what is published. These look at what is reachable, and at what you’d need to certify.
Stage 02 · Getting compliant
Cyber Essentials readiness assessment
See how close you are to certification.
Coming soon
Stage 04 · Mature, want to improve
Attack surface assessment
Find and close gaps.
Coming soon

Want someone to walk through your result?
Send us the domain and we’ll go through the findings with you — what matters, what can wait, and what it takes to close each one.
- 16 Jalan Kilang Timor, #04-06 Redhill Forum, S159308
- [email protected]
- +65 8749 4825