Free tools · No account needed
HSTS, Content-Security-Policy, X-Frame-Options and the rest: the headers that protect your visitors, with a grade and what is missing.
Example: tusitio.pe or https://www.tusitio.pe. Takes a few seconds.
They stop whole classes of attacks (clickjacking, content injection, downgrade to HTTP) at zero cost. Security scanners and some clients ask for them.
In Apache with .htaccess, in Nginx with add_header, or from the application. Cloudflare can also inject them.
Content-Security-Policy can, if it is too strict. Start with report-only mode and enforce it when the reports are clean.
Everything at once, with a grade from A to F.
See every DNS record of a domain: A, AAAA, CNAME, NS, MX, TXT, SOA and CAA, as our resolve...
Registrar, creation and expiry dates, nameservers and transfer lock of any domain. The exp...
Is the certificate valid, who issued it, when does it expire and which TLS versions does t...
IP address, country, network and the hosting provider we deduce from it. Also whether the...
MX, SPF, DKIM and DMARC. If any of these is missing, anyone can send email in your name, a...
Where does a URL end up, and through how many hops. Redirect chains slow every visit down...
Meta robots, X-Robots-Tag header and robots.txt. Launching a site with a "noindex" left ov...
We request the site right now from our server and tell you the status code and the respons...