Free tool
Basic domain security checker
Bring basic public controls into one response to guide the next review without port enumeration or private-network scanning.
Check domain
What it checks
TLS
Certificate served on 443 and validation outcome.
DNS
Resolution, delegation, mail, CAA, and TXT.
Basic SPF presence and DMARC policy.
How to interpret the limits
No exploitation, port enumeration, or vulnerability scanning.
Does not validate DKIM because each sender has its own selector.
A clean result is not a security guarantee or a substitute for monitoring.
Safe use and privacy
Enter only public domains you are authorized to review. Queries are not stored; private IPs, localhost, reserved ranges, and mixed destinations are blocked. Results are point-in-time public metadata.
Frequently asked questions
Is the queried domain stored?
No. The tool processes the lookup to respond and does not persist the domain or result.
Can I check an IP or internal service?
No. Only public domains are accepted; direct IPs and private, local, or reserved destinations are blocked.
Move from a check to monitoring
A spot check helps diagnosis. Monitoring keeps history and warns you when evidence changes.
Explore modulesRelated content
Certificate lifecycle
SSL/TLS certificate monitoring and expiration alerts
Monitor SSL/TLS certificates across multiple domains, receive expiry alerts, and detect unexpected certificate-chain or TLS posture changes.
Domain trust
DNS and email security monitoring
Detect DNS record changes and monitor SPF, DKIM, DMARC, MX, nameserver, MTA-STS, and TLS-RPT posture across your domains.
Email authentication
DMARC monitoring and RUA report analysis
Receive and analyze DMARC RUA reports, identify sending sources, and track SPF/DKIM alignment before tightening domain policy.
External discovery
External attack surface management (EASM)
Discover subdomains and internet-exposed assets related to authorized domains, prioritize findings, and monitor external attack-surface changes.