Website / HTTPS-TLS
Certificate chain, validity & hostname, key strength, TLS versions (1.0–1.3), cipher suites & Perfect Forward Secrecy, DANE/TLSA, revocation & Certificate Transparency, HTTP/2 & HTTP/3, and HTTP→HTTPS redirect. How it's scored →
A single test for website, HTTP security headers, email authentication, mail server, DNS, and DNSSEC – more than 100 individual checks from leading tools, combined into one report.
No tracking, no cookies. Results are cached for up to 1 hour, then discarded.
Certificate chain, validity & hostname, key strength, TLS versions (1.0–1.3), cipher suites & Perfect Forward Secrecy, DANE/TLSA, revocation & Certificate Transparency, HTTP/2 & HTTP/3, and HTTP→HTTPS redirect. How it's scored →
HSTS incl. preload, Content-Security-Policy & Trusted Types, clickjacking protection, cross-origin isolation (COOP/COEP), Referrer & Permissions Policy, cookie flags & prefixes (__Host-/__Secure-), Subresource Integrity, security.txt, and information leaks. How it's scored →
SPF (including lookup limit and include targets), DKIM selectors & key length, DMARC policy, subdomain policy & report authorization, BIMI, Null MX, MTA-STS, and TLS-RPT. How it's scored →
STARTTLS support of the MX hosts, negotiated TLS version and cipher suites, certificates, reverse DNS (FCrDNS), Null MX, and DANE/TLSA verification against the actual server certificate. How it's scored →
Number & IPv6 reachability of the name servers, RPKI, open zone transfers (AXFR), A/AAAA, HTTPS records, MX, CAA, SOA, and reverse DNS. How it's scored →
Zone signing, DS anchoring at the parent, validation via the AD flag, algorithm strength, RRSIG time remaining, authenticated denial (NSEC/NSEC3), and automated DS maintenance (CDS/CDNSKEY). How it's scored →
Prefer to focus on one area? Run an individual security test by topic.
The checks are based on established standards and best practices, including RFC 8446 (TLS 1.3), RFC 9000 (QUIC/HTTP/3), RFC 7208 (SPF), RFC 6376 (DKIM), RFC 9989 (DMARC, formerly 7489), RFC 8461 (MTA-STS), RFC 8460 (TLS-RPT), RFC 6698/7671/7672 (DANE), RFC 4033 ff. (DNSSEC), RFC 8659 (CAA), RFC 9116 (security.txt), RFC 6797 (HSTS), and the OWASP recommendations for security headers.
Transparency: see the full list of TLS cipher suites we probe, the root CAs we trust, and how this tool compares to SSL Labs, internet.nl, Hardenize & co.