Website Security Scanner

Enter your domain to run a defensive security assessment checking HTTPS/TLS, headers, DNS, cookies, exposed services, and OWASP-oriented misconfigurations.

Advertisement

What We Scan For

🔒

HTTPS & TLS

Certificate validity, issuer, expiry, TLS version support, cipher strength, and HTTPS redirect configuration.

🛡

Security Headers

CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and more.

🌐

DNS & Email

SPF, DKIM, DMARC, DNSSEC, MX records, and DNS configuration that affects email security and deliverability.

🍪

Cookie Security

HttpOnly, Secure, SameSite flags on cookies that can expose session data to client-side attacks.

Web Misconfigs

Common web server misconfigurations, exposed technologies, redirect chains, and publicly observable issues.

📋

OWASP-Oriented

Checks aligned with OWASP Top 10: security misconfiguration, broken access control indicators, and more.

Safe and Non-Destructive
This scanner performs only publicly observable, passive checks. It does not attempt to exploit vulnerabilities, modify any data, or send authenticated requests. It is a defensive assessment tool, not an offensive exploitation platform.