Scan a website and see what an attacker sees, mapped to the Essential Eight. Or, with no account at all, check a password against billions of leaked credentials and find out whether someone can send email as your business.
Passive vulnerability scan of any URL, security headers, TLS, CORS, JWT and outdated JavaScript libraries.
Launch scannerScans a website, checks its email authentication, and fills in the Essential Eight and cyber insurance audit with everything the results can answer. What a scan cannot see is marked for a person.
Scan and populate the auditCan someone send email pretending to be your business? Reads your SPF, DKIM and DMARC records and gives a plain-English answer. No account needed.
Check my domainSee whether a password has appeared in a public data breach. Runs entirely in your browser, and the password is never sent to us.
Check a passwordPaste Mermaid or UML code, flowcharts, sequence, class, state and ER diagrams, and get a clean SVG. Renders in your browser; the code never leaves the page.
Open rendererHas a service your firm relies on been breached? Type its domain, see when, how many accounts, and whether passwords leaked. No personal data is sent anywhere.
Check a servicePaste the headers of a suspicious email and see where it really came from, whether SPF, DKIM and DMARC passed, and the signs of a fake. Processed in memory, never stored.
Analyse an emailWhich typos and lookalike spellings of your domain has someone already registered, and which of them are set up to send email in your name.
Find lookalikesWhen your domain expires, who the registrar is, whether transfer lock is on, and whether your personal details are in the public record.
Check a domainFinished a workshop lab? Verify your AWS resources step by step with read-only checks, and get a hint for anything that fails.
Open lab checkerInspect a host's certificate and TLS configuration: expiry, protocol versions, weak ciphers and missing HSTS.
Check TLS