DNS and domain security check
Reads your domain’s DNS posture: is the DNSSEC signature validating, which authorities may issue certificates (CAA), are the name servers redundant, when does the registration expire and is there a transfer lock. No ownership needed, no request to your server.
Other tests
Security headers test
Grades HSTS, CSP depth, CORS, SRI, mixed content and cookie settings.
SSL/TLS check
Certificate chain, protocols, weak ciphers.
Email security check
SPF, DKIM and DMARC: can someone send fake email in your name?
Attack surface reconnaissance
Passive OSINT: subdomains, dangling records, technology stack, DNS and ASN; what an attacker sees during recon.
Subdomain scanner
Every subdomain of your domain: resolution, first seen, dangling records and takeover signals.