Check a vendor without asking them anything
Enter a domain and get a posture snapshot in about three seconds. Built only from public DNS. No account, no scanning, and no request of any kind reaches the domain you are checking.
Want the extended version?
The snapshot above covers DNS. The extended report adds certificate transparency history, published security headers, TLS configuration, breach corpus matches and the sub-processors the domain reveals. It needs a server-side lookup, so we email it.
Your email is used to send this report. It is not sold, and there is no drip sequence attached to it. See the privacy policy.
This tool is passive and non-intrusive. Every lookup goes to a public DNS resolver, never to the domain being checked. No packet reaches that organisation's infrastructure, nothing is scanned, no port is probed and no login is attempted. It reads the same public records any recipient mail server reads before accepting a message.
What it checks, and why each one matters
- DMARC
- Whether mail claiming to come from this domain gets rejected. A domain at
p=noneis publishing a policy that instructs recipients to do nothing, which is the most common gap we find. - SPF
- Who is authorised to send on the domain's behalf, and whether unlisted senders hard fail or merely get a shrug.
- CAA
- Which certificate authorities may issue for the domain. With no CAA record, any public CA can.
- DNSSEC
- Whether DNS answers are signed, which makes tampering detectable.
- Mail provider
- Who actually handles their mail. That provider is one of their sub-processors, and by extension usually one of yours.
What it deliberately does not do
Worth being explicit, because a security company caught scanning without authorisation would deserve everything that followed.
- No port scanning and no service fingerprinting.
- No authentication attempts of any kind.
- No crawling, and nothing that ignores robots.txt.
- No requests to the checked domain at all, rate limited or otherwise.
- No storage of the domains you check beyond your own browser session.
A clean result is not a clean bill of health
Five green rows mean five specific public records are configured well today. It says nothing about what happens inside that vendor, and this tool does not pretend otherwise. What it is good for is the opposite signal: a domain that cannot get DMARC right is unlikely to have the harder things right either, and now you know to ask.
Run it across every vendor, every day
One domain is a snapshot. The value is in re-checking your whole supplier register on a schedule and being told the day an answer changes.
Talk to us about your register