Eight modules behind every letter.

Scans run against domains you have added, from your dashboard, on a schedule you set. Here is exactly what each one looks at.

Passive — nothing to verify.

These read publicly broadcast data, exactly like a browser does. They run the moment a target is added.

  • Security headers18 HTTP headers · copy-paste fixes for nginx, Apache and Caddy
  • SSL / TLSChain, ciphers, forward secrecy, HSTS, expiry alerts
  • DNS recordsA, AAAA, MX, NS, TXT, CNAME, SOA · DNSSEC enforcement
  • Email securitySPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI · scored 0–100
  • Technology5,000+ stacks fingerprinted, versions extracted for CVE matching
  • Subdomainscrt.sh and AlienVault OTX · surfaces forgotten staging hosts

Active — ownership verified first.

These probe the target server, so we ask you to prove the domain is yours to audit — a DNS TXT record or a file at the web root. Two minutes, once.

  • Open portsConcurrent scan with service identification
  • Service bannersSSH, HTTP, FTP, SMTP, POP3, IMAP, MySQL fingerprinting
Read the acceptable use policy

Ready to grade your first client site?

Add a domain, run the scan, hand over a PDF with your logo on it.