Scan any domain security posture — SSL/TLS, security headers, email authentication, DNS health, breach history, and privacy — into one clear risk score.
This tool runs a broad security posture scan against a single domain and rolls the results into a readable risk picture. Instead of checking one thing in isolation, it samples the layers an attacker (or a careless misconfiguration) would touch first:
Individually, each finding is minor. Together they describe real exposure. A site with a valid certificate but no HSTS and a ~all SPF record is still trivially phishable and downgrade-able. Scanning everything at once lets you triage: fix the high-impact, low-effort items (DMARC enforcement, HSTS, missing CSP) before chasing edge cases.
Treat the score as a prompt, not a verdict. Email authentication and HTTPS enforcement gaps are the items most often weaponized in real attacks, so weight those first. For a deeper look at any certificate the scan flags, the X.509 Certificate Decoder breaks a cert down field by field, including its validity window and signature algorithm.