Principle Security Principle Security.

Free, instant, no signup

Could someone spoof your email or hijack your domain tonight?

Enter a domain. We grade the fifteen public settings that decide whether your mail can be forged, your DNS answers trusted, your site connections downgraded, and your domain transferred away without you. Read-only, public data only, exactly what an attacker or an examiner would look at first.

Email spoofing

SPF, DMARC policy and enforcement, DKIM selectors, MTA-STS and TLS-RPT. The settings that decide whether a forged invoice from your domain reaches a member.

DNS integrity

DNSSEC signing and CAA issuance limits. Unsigned zones can be forged; without CAA any public CA will issue a certificate for your name.

Web transport

Certificate validity, deprecated TLS 1.0/1.1, HTTP to HTTPS redirect, HSTS, and the security headers browsers rely on.

Domain hijack

Registrar transfer locks and expiry from the RDAP registry record. The two facts that decided a recent credit-union domain takeover.

Everything here is passive: DNS lookups over public resolvers, one TLS handshake with your own website, two page requests, and a registry query. Nothing is scanned, probed, or logged in. The checks and the grading are the same ones we run in client engagements, so the grade you see is the grade an examiner-style review would give for these controls.

Want the gaps closed, not just graded?

Most of what this check finds is a two-hour fix with the right runbook. We do it as part of a fixed-fee posture sprint for credit unions and community banks, with the evidence your examiner asks for.