Frequently asked questions

The most common questions about the free domain security check: cost, privacy, what is checked, how the grade is calculated, and how the tool compares to single-purpose scanners.

Is Domain Security Check free?

Yes. It is a private, non-commercial project: no cost, no signup, no advertising, no affiliate links.

What exactly is checked?

Six modules in one scan – more than 100 individual checks: website HTTPS/TLS (certificates, protocol versions, ciphers, forward secrecy), mail server STARTTLS and DANE/TLSA, email authentication (SPF, DKIM, DMARC, BIMI, MTA-STS, TLS-RPT), DNSSEC, general DNS hygiene, and HTTP security headers.

Do you store scan results or track visitors?

No tracking and no cookies. Scan results are cached for up to one hour so repeated checks don't re-probe your servers, then discarded.

How is the grade calculated?

Each check yields a weighted finding; the weighted score maps to a letter grade from A+ to F. Serious single findings cap the module grade regardless of the average (rating caps modeled on the SSL Labs Server Rating Guide) – for example an expired certificate caps at F. Full methodology →

How is this different from SSL Labs or securityheaders.com?

Those tools each cover one aspect. This scan combines the most important checks of SSL Labs, securityheaders.com, internet.nl, Hardenize, Mailhardener and DNSViz-style DNSSEC analysis into a single report for the whole domain. Detailed comparison →

Can I see or block the scanner in my logs?

Yes. HTTP requests carry a stable User-Agent token linking to the scanner page, and all probes come from fixed, published IP addresses with matching reverse DNS. Identify & block the scanner →