HackproofHacks
Free tool · Full scan

Free Website Security Scan

One scan, one grade. We check your HTTP security headers, your TLS certificate, and whether SPF and DMARC stop anyone else from sending email as you, then combine all three into a single A+ to F score. The score is free. Enter your email and we unlock every finding, with the exact fix, and send the full report to your inbox too.

Only run this against domains you own or are authorised to test.

How this works

This scan runs three checks that usually live in three separate tools and rolls them into one grade: the HTTP security headers your site sends, the TLS certificate it is serving, and whether SPF and DMARC are set up so nobody can send email that looks like it is from you. You see the grade and how many issues turned up right away. Enter your email and we send the full list, each one with the exact fix, straight to your inbox.

One grade instead of three separate checks

Most people checking their own site end up running three or four different tools and trying to weigh the results themselves: an A on headers, a B on the TLS certificate, no clear read on what SPF or DMARC even do. This scan runs all three checks in one pass and combines them into a single score, so you get one number, and, once you unlock the full report, one prioritised list of what to fix first.

It is built on the same engines behind our HTTP header analyzer and SSL checker, so nothing here is a lighter, worse version of those tools. Email-spoofing protection is checked directly: whether your domain publishes an SPF record, whether DMARC is set up, and whether that DMARC policy actually blocks unauthorised mail or just watches and reports on it.

A scan checks the surface. Want the whole thing checked?

This tool catches the misconfigurations that are easy to automate. It cannot test your login flow, your API's access control, or the business logic that real breaches actually exploit. If you want that covered, talk to our penetration-testing team.

Get a professional review

Free security scan — frequently asked questions

What does the free scan actually check?

Three things: the HTTP security headers your site sends (the same checks our header analyzer runs), the TLS certificate it is serving, and whether SPF and DMARC are set up to stop someone else from sending email that looks like it came from your domain. Each one gets its own score, and the three combine into a single grade.

What is free, and what needs my email?

The grade, the score breakdown by category, and how many critical issues turned up are free and appear the moment the scan finishes. The full list, with a plain-English explanation of the risk and the exact fix for each finding, is what you get by entering your email. We send that same list to your inbox too, so you have a copy.

Do you store the domains people scan?

We keep the report for an hour so the email-unlock step has something to attach the results to, then it is discarded. If you do unlock a report, we keep the lead: your email, the domain, and the score, the same way we keep every other form submission on this site. Scan results are never published or indexed.

Is this the same as a penetration test?

No, and that is on purpose. This scan automates the checks that can be automated: headers, certificates, DNS records. A real penetration test is a person working through your login flow, your API, and your business logic by hand, looking for the kind of flaw a scanner has no way to notice. If the free scan turns up something concerning, that is usually a sign it is worth booking the deeper version.

Will running this against my site cause any problems?

No. Every check here reads information a normal visitor already reads: response headers, the certificate your server presents, and public DNS records. Nothing sends traffic your server would treat as unusual, so it is safe to run against a production site.