Pentest Today.

Free · no account

What can the internet already see?

Enter a domain and we'll check what's exposed from the outside — certificates, DNS, email authentication, and security headers.

Passive checks only — public DNS, TLS, and headers. No account needed, and nothing is sent that a browser wouldn't.

What we check

  • TLS certificateexpiry, and whether it covers the hostname
  • HTTPSwhether the host serves it at all
  • Email authenticationSPF and DMARC, and whether they enforce
  • Security headersCSP, HSTS, framing, MIME-sniffing, referrer
  • Version disclosuresoftware versions leaked in responses

All of it is public information, gathered the way a browser would. Nothing here touches the application itself — that's the full pentest, which needs your authorization first.