Website Security Scanner
Enter your domain to run a defensive security assessment checking HTTPS/TLS, headers, DNS, cookies, exposed services, and OWASP-oriented misconfigurations.
What We Scan For
HTTPS & TLS
Certificate validity, issuer, expiry, TLS version support, cipher strength, and HTTPS redirect configuration.
Security Headers
CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and more.
DNS & Email
SPF, DKIM, DMARC, DNSSEC, MX records, and DNS configuration that affects email security and deliverability.
Cookie Security
HttpOnly, Secure, SameSite flags on cookies that can expose session data to client-side attacks.
Web Misconfigs
Common web server misconfigurations, exposed technologies, redirect chains, and publicly observable issues.
OWASP-Oriented
Checks aligned with OWASP Top 10: security misconfiguration, broken access control indicators, and more.
This scanner performs only publicly observable, passive checks. It does not attempt to exploit vulnerabilities, modify any data, or send authenticated requests. It is a defensive assessment tool, not an offensive exploitation platform.