Run a complete security audit on any website in seconds. Check SSL certificates, DNS health, security headers, blacklist status, and exposed API keys. Get an A+ to F grade with plain-English explanations. Free to use - no signup required.
Verify certificate validity, expiration date, issuer, and chain. Get warnings before certificates expire.
Check SPF, DKIM, DMARC, DNSSEC, and CAA records. Essential for email deliverability and preventing spoofing.
Analyze HSTS, Content-Security-Policy, X-Frame-Options, and other security headers that protect against attacks.
Scan your public JavaScript for exposed API keys - AWS, Stripe, Firebase, OpenAI, GitHub tokens, and 212+ patterns.
Verify your domain is not listed on spam or malware blacklists (Spamhaus, SURBL, URIBL, SpamCop, Barracuda).