Skip to main content
Website Scanner · Online

Website Scanner:
scan your domain for security — free

Run a free security scan on any website in ~15 seconds. This website scanner doubles as a domain scanner: SSL, HTTP headers, DMARC/SPF, DNS records and open ports — one website scan, one clear report.

free  ·  no account needed  ·  result in ~15 sec

What does the website scanner check?

A complete website scan is more than one test. The scanner runs every check below against your domain at once and combines them into a single security check with a grade from A to F. Need only one aspect? Each area also has its own dedicated tool.

SSL/TLS certificate

The scanner fetches your TLS certificate and checks issuer, remaining validity, protocol version and cipher. An expired certificate or active TLS 1.0/1.1 triggers a full-page browser warning — visitors bounce before they see your site. Test it individually with the SSL check.

HTTP security headers

The HTTP response is inspected for the six most important security headers, from HSTS to the Content-Security-Policy. Missing headers leave the door open for clickjacking, XSS and downgrade attacks. Dedicated tool: security headers check.

Email protection (SPF, DKIM, DMARC)

Via DNS, the scan reads SPF, DKIM and DMARC — the three records that decide whether your domain can be abused for phishing. Without an enforcing DMARC policy, practically anyone can send mail in your name. Dedicated tool: DMARC checker.

DNS records

All relevant record types (A, AAAA, MX, NS, TXT, SOA) are read out, including the CAA record and DNSSEC status. Faulty DNS is the classic cause of unreachable sites and vanished email. Dedicated tool: DNS lookup.

Open ports

Twenty common TCP ports are tested for reachability. Critical admin and database ports — SSH, RDP, MySQL, Redis, MongoDB — are flagged red, because exposed to the internet they are a direct way in. Dedicated tool: port scanner.

Cookies & GDPR

The scan reads every cookie set on the first visit, checks the Secure, HttpOnly and SameSite flags and detects tracking cookies that load before consent — the most common GDPR trap. Dedicated tool: cookie checker.

Domain data & software

The WHOIS/RDAP lookup shows registrar, status and expiry date of the domain — an unnoticed lapse means someone else can take it over. On top, the scanner detects the software in use (CMS, server) and matches versions against known vulnerabilities (CVEs).

How to read your scan result

Every website scan produces one report: a score from 0 to 100 with a grade from A to F at the top, followed by the individual findings. Each finding carries a severity — Critical and High mean act now (an expired certificate, an exposed database port), Medium is a real gap without immediate danger (a missing security header), Low and Info are hardening tips and context.

You don't have to prioritise yourself: the report highlights quick wins — findings with the best ratio of effort to score impact — and every finding comes with a concrete step-by-step fix, including the estimated effort and, where useful, ready-to-paste configuration. With a free account you can download the whole report as a PDF and re-scan later to see the score improve.

Common findings — and how to fix them

  • HSTS missing: the most frequent finding of all — and one line of server configuration fixes it. What HSTS does and how to set it.
  • No DMARC record: your domain can be spoofed for phishing. Start with a p=none policy to collect reports, then tighten to quarantine or reject. DMARC explained step by step.
  • No Content-Security-Policy: the strongest browser-side defence against XSS is missing. Introduce it in report-only mode first so nothing breaks. How a CSP is built.
  • Session cookies without Secure/HttpOnly: cookies are easier to steal via XSS or on unencrypted connections. Usually a one-line change in the framework config. The three cookie flags explained.
  • Certificate about to expire: under 30 days remaining means renew now — or better, automate it with Let's Encrypt so this finding never returns. How SSL/TLS certificates work.

What this scanner is not

The scan is deliberately non-invasive: it sends normal HTTP(S) requests and DNS queries, the same way a browser or mail server would — no exploit attempts, no login brute-forcing, no load testing. That makes it safe to run against any domain, but it also means it is not a penetration test: it finds missing safeguards in your configuration, not logic flaws in your application.

It is also not a malware scanner — it doesn't inspect your files for infections — and no automated check replaces a professional security audit for high-risk applications. Think of it as the technical baseline: the things every website should have in order before anything else.

Want everything in one report? The full Webscan Radar security scan combines all areas plus GDPR audit, CMS detection and CVE matching — also free, no account. Or browse all single-check tools and the security lexicon.

Website scanner — frequently asked questions

What does the website scanner check?

The website scan covers your SSL/TLS certificate, HTTP security headers (HSTS, CSP, X-Frame-Options and more), DMARC/SPF/DKIM email protection, DNS records, open ports, cookies and known CVEs in detected software — a full security check in one pass.

Is the website scanner free?

Yes. You can scan any domain for free without an account. A free email registration only unlocks the full PDF report and your scan history.

Do I need an account to run a scan?

No. The scan itself runs without any registration. A free account unlocks the full PDF report, your scan history and continuous monitoring of your domains — but the scan and the on-screen report work without it.

How long does a website scan take?

Usually 10 to 20 seconds. Complex domains with many subdomains or slow DNS servers can take up to a minute.

Is my scan data stored?

Only the technical scan result for the domain is stored, so you can revisit and share the result URL. Result pages are not publicly listed and are blocked from search engines (noindex). With an account you can delete your scans at any time.

Is it a website scanner or a domain scanner?

Both. You enter a domain (e.g. example.com) and the scanner checks the website and the domain's DNS, mail and certificate setup in a single website scan.