Free Domain Security Check
The free front door to External Security — our outside-in protection for everything attackers can see. Run a free scan that checks over 40 points across your email security, web and TLS, external exposure, attack surface, and brand. No install, no sign-up, no access to your systems.
Over 40 checks, across six fronts
Most free scanners look at SPF and a TLS certificate and call it a day. This one runs the same comprehensive passive assessment we use in our paid audits, on every scan, entirely from the outside. Here is exactly what it looks at.
Email Security
Can anyone send mail as you, and does yours get delivered?
- SPF record & policy
- SPF lookup budget
- SPF hygiene
- DKIM signatures & selectors
- DKIM key strength
- DMARC policy & enforcement
- DMARC reporting
- MTA-STS policy
- MTA-STS enforcement mode
- TLS-RPT reporting
- BIMI verified logo
- ARC forwarding integrity
- Reverse DNS (FCrDNS)
- Mail-server IP reputation
- Mail delivery resilience
- DNSSEC
Web & TLS
Is your website configured safely?
- TLS version & ciphers
- Certificate health & expiry
- TLS hardening grade
- HSTS
- Content-Security-Policy
- Clickjacking protection
- MIME-sniffing protection
- Referrer-Policy
- Permissions-Policy
- Cookie security flags
- Mixed content
- Server version disclosure
- Security-header depth
- CAA records
External Exposure
What can an attacker discover about you?
- Subdomain discovery
- Subdomain-takeover exposure
- Certificate Transparency exposure
- DNS zone-transfer (AXFR)
- Wildcard DNS
- Nameserver diversity
- Domain expiry
- Registrar transfer lock
- security.txt disclosure policy
Additional context
Extra intelligence we surface, for context.
- Microsoft 365 footprint
- Staff email-address pattern
- Hostname naming exposure
- Compliance framework alignment
Identity & Brand
Who could impersonate you?
- Look-alike domains
- Mail-enabled lookalike abuse
Attack Surface
Can your infrastructure absorb an attack?
- DDoS scrubbing coverage
The scanner runs entirely from outside your network, the same view an attacker has. It reads publicly available DNS records and public-facing services only. It never sends test emails, never logs in to anything, and never touches your internal systems.
What the big findings mean for you
Email authentication: SPF, DKIM and DMARC
SPF tells receiving mail servers which systems are authorised to send email for your domain. DKIM adds a cryptographic signature so recipients can verify messages have not been tampered with. DMARC ties these together and tells receiving servers what to do when a message fails. Without an enforced DMARC policy, your domain can be spoofed and used in phishing attacks against your own customers, suppliers, and staff.
Web and TLS health
The scan checks your TLS certificate validity and configuration and the presence of key HTTP security headers such as HSTS and Content-Security-Policy. Weak or expired certificates and missing headers are among the most common findings in external security assessments, and they directly affect whether browsers and customers treat your site as safe.
External exposure
Subdomains created for old projects and never decommissioned stay visible to attackers. The scan maps the subdomains and services associated with your domain to show what is publicly facing. Forgotten DNS records pointing at decommissioned infrastructure are a well-documented source of subdomain takeover vulnerabilities.
Built for UK businesses, free to run
More than four in ten UK businesses identified a cyber attack or breach in the past year, and phishing remains by far the most common type (UK Government Cyber Security Breaches Survey 2025/26). Misconfigured or missing SPF, DKIM and DMARC records mean your domain can be used to phish your own customers and suppliers without your knowledge.
The check is designed for IT managers, operations leads, and business owners who want a quick external view before a board update, a tender submission, a Cyber Essentials assessment, or a conversation with a security partner. The results are written in plain English, so you do not need to be technical to act on them.
Domain security, answered
What is DMARC and why does my business need it?
DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receiving mail servers what to do when an email claims to come from your domain but fails authentication. Without an enforced DMARC policy, criminals can send convincing phishing emails to your customers, suppliers, and staff that appear to come from you. The NCSC recommends DMARC as a baseline control for UK organisations.
What is the difference between SPF, DKIM and DMARC?
SPF lists which mail servers are allowed to send email for your domain. DKIM adds a cryptographic signature to outgoing messages so recipients can verify they have not been tampered with. DMARC ties the two together and sets a policy telling receiving servers to quarantine or reject messages that fail. All three working together is the standard the NCSC recommends. For the full picture, read our plain-English guide to SPF, DKIM and DMARC.
Will running this scan affect my website or email?
No. The scan is passive and external. It reads publicly available DNS records and checks your public-facing web services, the same information anyone on the internet can already see. It does not send test emails, log in to anything, or touch your internal systems.
What happens to the information I enter?
The scan uses only publicly available DNS and web data. We keep the scan results so we can generate your report, and if you ask us to email it to you we store your address to send it and to follow up once. We never sell or share your details with third parties. See our privacy policy for full detail.
What do I get in the emailed report?
The instant result shows your overall score, rating, and how many issues were found. Your emailed report, sent as a private link, breaks down every finding with a severity rating and explains in plain English what each one means, across email security, web and TLS, external exposure, attack surface, and brand. The step-by-step fix for every issue comes with the £50 full report, downloadable as a PDF.
Found something you want fixed?
Get the £50 full report and you'll have the exact fix for every finding, prioritised and ready to action. A free scan commits you to nothing.
Specifically worried about email impersonation and DMARC? Our Managed DMARC service walks your domain safely to full enforcement, done for you.
