Check SPF, DMARC, DNSSEC, CAA records, open ports, and CVE exposure. Uses Google DNS over HTTPS and Shodan InternetDB.
Checks SPF, DMARC, DNSSEC, CAA records, open ports, and CVE exposure via Google DNS and Shodan InternetDB.
Runs a series of DNS and exposure checks against any domain: SPF, DMARC, DNSSEC, HSTS, and CAA records — the five controls most commonly reviewed in an external security assessment. It also queries Shodan InternetDB for open ports and associated CVEs.
SPF and DMARC control whether your domain can be spoofed in phishing emails. DNSSEC authenticates DNS responses. HSTS prevents protocol downgrade attacks. CAA limits which certificate authorities can issue certificates for your domain.
Use this as a first-pass external posture check on any domain you own, manage, or are assessing. It surfaces the low-hanging fruit that shows up in almost every external penetration test and vendor security review.
A domain with missing SPF, no DMARC enforcement, and open legacy ports like 21 or 3389 is a domain that will appear in a findings report. This tool gives you that view in seconds without running a full scanner.