Skip to content
Free tool · no account

See what the internet
already knows about your domain.

An instant, passive exposure check. Enter a domain and get its DNS and hosting footprint, TLS certificate health, security headers, email spoofing protection and the subdomains sitting in public certificate logs — scored, with the specific things to fix.

Passive checks only, against public records. No account needed, nothing is sent to the target that a normal browser would not send.

What it looks at

Six checks, all from public records.

Nothing here touches your systems in a way an ordinary browser would not. That is the point: it is safe to run against any domain, including one you are about to have a conversation about.

01 · DNS and hosting

Which addresses answer for the name, who runs the nameservers, and where mail is routed. The starting map of what is exposed and who controls it.

02 · TLS certificate

Issuer, expiry date and negotiated protocol version. Expired certificates and deprecated protocol versions are among the most common findings in any external assessment.

03 · Security headers

HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy — the browser-side controls that are free to set and frequently unset.

04 · Email spoofing

SPF and DMARC, including whether the DMARC policy actually rejects anything or is sitting on p=none and only watching.

05 · Certificate-log subdomains

How many hostnames under your domain have appeared in public certificate transparency logs. Often the first time an organisation learns how large its own surface is.

06 · Risk score

A single number derived from the deductions above, with every deduction itemised. No black box, and no severity inflation.

Behind the free account

The half that costs money to answer.

Public records tell you how a domain is configured. They do not tell you which services are listening, which of those carry known vulnerabilities, or whose credentials for your domain are already circulating. Those answers come from commercial intelligence sources that charge per lookup.

We are explicit about this rather than pretending the free tier is the whole picture. Running paid lookups for anonymous traffic is how free tools get abused until they are withdrawn. An account makes each lookup attributable and rate-limited — and it is free.

Create a free account
account tier
Open ports and exposed services
What is actually listening, with service banners
Known CVEs on those services
Matched against the versions detected
Leaked credential exposure
Corporate credentials found in breach corpora
Full subdomain inventory
Not just the count — the list
Scheduled re-checks
Alerts when the surface changes
Questions

What people ask before running it.

Is this free attack surface check really free?
Yes, and it needs no account. Every check on the free tier is computed from public records — DNS, certificate transparency logs, the TLS handshake and the HTTP response headers your site already returns to any browser. Those cost nothing to run, so there is no reason to charge or to gate them. The checks that query paid intelligence sources per lookup — open ports, service CVEs and leaked credentials — sit behind a free account so they can be attributed and rate-limited.
Is it legal to scan a domain I do not own?
This tool performs passive reconnaissance only. It reads public DNS records, public certificate transparency logs, and the response your web server gives to an ordinary HTTPS request. It does not port scan, send payloads, attempt authentication or probe for vulnerabilities, so it stays within what any browser or search crawler already does. The active checks — the ones that would need authorisation — are the ones we put behind an account.
What does the score actually measure?
It starts at 100 and deducts for specific, named weaknesses: missing or weak security headers, an expired or short-dated TLS certificate, a deprecated TLS protocol, and missing SPF or DMARC records. Every deduction appears in the "what to fix" list, so the number is never a black box. It measures hygiene visible from outside, not whether you can be breached — a perfect score here says nothing about your application logic or your internal network.
Why can it not see my open ports and CVEs for free?
Those answers come from commercial intelligence sources that bill per lookup. Running them for anonymous traffic would mean spending real money on requests nobody can be held to, which is exactly how free tools get abused into oblivion. A free account gives you a rate-limited allowance and a record of who ran what.
Do you store the results?
No. The free check runs on request and returns the result to your browser. Nothing is written to a database and no report is retained. If you want results kept, compared over time, or alerted on when they change, that is what the account-based monitoring does.
Can I use this to show a prospect their exposure?
That is one of the most common uses. Service providers run it live on a call against a prospect domain to open the conversation with something concrete rather than a generic pitch. Because it is passive and public-records-only, it is safe to run in front of someone before any authorisation paperwork exists.
Next

Configuration is the easy half. The rest needs a test.

An exposure check tells you what is visible. A penetration test tells you what can be done with it. See how the engine behind this tool runs a full assessment.