SOC status:Duty analyst on shift

UK Cyber Defence

Tools / External Exposure

What does the internet see when it looks at you?

The eight free checks on this site, run together against one domain and read as one report: whether your email can be forged, what your DNS gives away, how your website’s encryption, headers and cookies hold up, what the certificate logs remember, whether researchers can reach you, and what the threat feeds say about your name and addresses. One grade, the fixes in order, and a PDF to hand to whoever needs to see it.

Email · DNS · TLS · Reputation · Security headers · Certificate transparency · Cookies and consent · security.txtFree · No sign-up to run · PDF for a name and email

The eight areas

Email · 20% of the grade

Can someone send email as you? SPF, DKIM and DMARC as a receiver evaluates them, MTA-STS and TLS-RPT, and a plain answer: spoofable, partly, or not.

The standalone tool →

DNS · 15% of the grade

What do your records give away, and are they secure? Private addresses in public records, dangling names, zone transfers, DNSSEC, lame delegation, and the tokens and comments people leave in TXT.

The standalone tool →

TLS · 15% of the grade

Is the encryption on your website sound? Certificate trust and expiry, protocols from SSL 2 to TLS 1.3, every cipher suite offered, forward secrecy and key strength, graded like SSL Labs.

The standalone tool →

Reputation · 15% of the grade

Are your domain and addresses on anyone's list? The domain and the addresses it resolves to against nine threat feeds, four mail blocklists, the URLhaus and ThreatFox host lists and the registries.

The standalone tool →

Security headers · 10% of the grade

Does the site defend the browser? HSTS, Content-Security-Policy, X-Frame-Options and the rest, graded A+ to F with the line that fixes each one.

The standalone tool →

Certificate transparency · 10% of the grade

What have the certificate logs recorded about you? Every host name that has ever had a certificate, which still resolve, which point at private addresses, which expire soon, and whether CAA agrees with the issuers.

The standalone tool →

Cookies and consent · 10% of the grade

What does the site do before anyone clicks accept? A first visit in a real browser: cookies set, trackers fired and third-party scripts loaded before consent, and whether the consent platform actually gates them.

The standalone tool →

security.txt · 5% of the grade

When someone finds a hole, who do they tell? Whether a security.txt exists at the well-known address with a current contact, a canonical URL, a key and a signature.

The standalone tool →

How to read it

Each area keeps the grade its own tool would give, so nothing is hidden in an average, and the overall score is a weighted mix that puts email first: forged email is still the cheapest way into most organisations, and the fix is three DNS records. A single critical finding anywhere — a private address in public DNS, a domain that anyone can send as, a botnet listing — caps the overall grade at C until it is closed, because that is the finding an attacker would use first, whatever else is right.

The report is read-only. It sends ordinary DNS queries, reads certificates and headers over a normal HTTPS connection, loads the home page once in a browser to see what happens before consent, and reads public logs, feeds and registries. It does not scan ports, test for vulnerabilities or touch anything behind the front door; that is what a penetration test is for. Think of this as the outside of the building at dusk: the open windows and the light left on, before anyone has tried a door.

Run it for your own organisation, for a supplier before you sign, or for the company you are about to acquire. It takes a minute, the findings link to the standalone report for each area, and the PDF is free for a name and a work email.