Free Domain Security Check
Find out in about 30 seconds whether a criminal could send email as you. See what else an attacker can see: your email set-up, your website, and old systems still on show. Over 40 checks. No sign-up, nothing to install. We never touch your systems.
What happens after the free check
- Free checkFree
See what is wrong and why it matters, in about 30 seconds. No sign-up, nothing to install.
- Full Report£50 one-off
The exact fix for every finding, in the order that matters, as a PDF you keep. Then keep it live with Monitoring for £29/month: a daily re-check and an email the day something slips. First month free.
- Or have us fix itFixed-price quote
We make the fixes for you and prove it with a before-and-after scan. No ongoing commitment.
Everything starts with the free check. Prefer to talk first? Ask us to fix it for you.
Over 40 checks, across six fronts
Most free scanners look at one or two settings and call it a day. This one runs every check we use in our paid audits, on every scan, entirely from the outside. Here is exactly what it looks at.
Email Security
Can anyone send mail as you, and does yours get delivered?
- SPF record & policy
- SPF lookup budget
- SPF hygiene
- DKIM signatures & selectors
- DKIM key strength
- DMARC policy & enforcement
- DMARC reporting
- MTA-STS policy
- MTA-STS enforcement mode
- TLS-RPT reporting
- BIMI verified logo
- ARC forwarding integrity
- Reverse DNS (FCrDNS)
- Mail-server IP reputation
- Mail delivery resilience
- DNSSEC
Web & TLS
Is your website configured safely?
- TLS version & ciphers
- Certificate health & expiry
- TLS hardening grade
- HSTS
- Content-Security-Policy
- Clickjacking protection
- MIME-sniffing protection
- Referrer-Policy
- Permissions-Policy
- Cookie security flags
- Mixed content
- Server version disclosure
- Security-header depth
- CAA records
External Exposure
What can an attacker discover about you?
- Subdomain discovery
- Subdomain-takeover exposure
- Certificate Transparency exposure
- DNS zone-transfer (AXFR)
- Wildcard DNS
- Nameserver diversity
- Domain expiry
- Registrar transfer lock
- security.txt disclosure policy
Additional context
What an attacker could work out about your people and systems.
- Microsoft 365 footprint
- Staff email-address pattern
- Hostname naming exposure
- Compliance framework alignment
Identity & Brand
Who could impersonate you?
- Look-alike domains
- Mail-enabled lookalike abuse
Attack Surface
Can your infrastructure absorb an attack?
- DDoS scrubbing coverage
The scanner runs entirely from outside your network, the same view an attacker has. It reads publicly available DNS records and public-facing services only. It never sends test emails, never logs in to anything, and never touches your internal systems.
What the big findings mean for you
Can someone send email pretending to be you?
Three settings decide it. One lists which systems may send email for your domain (SPF). One signs each message so it cannot be tampered with (DKIM). The third tells receiving servers to reject mail that fails (DMARC). Without that third setting enforced, criminals can phish your own customers, suppliers and staff in your name.
Is your website set up safely?
We check the certificate that proves your site is really yours, and the safety settings browsers look for. Weak or expired certificates and missing settings are among the most common findings in security assessments. They decide whether browsers, and customers, treat your site as safe.
What old or forgotten systems are still visible?
Web addresses created for old projects stay visible to attackers long after everyone else forgets them. The scan maps everything publicly on show for your domain. Forgotten records that point at switched-off systems are a well-known way in for an attacker.
Built for UK businesses, free to run
More than four in ten UK businesses identified a cyber attack or breach in the past year, and phishing remains by far the most common type (UK Government Cyber Security Breaches Survey 2025/26). Misconfigured or missing SPF, DKIM and DMARC records mean your domain can be used to phish your own customers and suppliers without your knowledge.
The check is designed for IT managers, operations leads, and business owners who want a quick external view before a board update, a tender submission, a Cyber Essentials assessment, or a conversation with a security partner. The results are written in plain English, so you do not need to be technical to act on them.
Domain security, answered
What is DMARC and why does my business need it?
It is the setting that tells the world's mail servers what to do with email that claims to come from you but fails the checks (DMARC). Without it enforced, criminals can send convincing phishing emails to your customers, suppliers and staff, apparently from you. The NCSC recommends it as a baseline for UK organisations.
What is the difference between SPF, DKIM and DMARC?
Three settings that work together. One lists which systems may send email for your domain (SPF). One adds a tamper-proof signature to each message (DKIM). The third ties them together and tells receiving servers to reject mail that fails (DMARC). All three together is the standard the NCSC recommends. Our plain-English guide covers the full picture.
Will running this scan affect my website or email?
No. The scan only reads what is already public: your DNS records and your public-facing services, the same information anyone on the internet can see. It sends no test emails, logs in to nothing, and never touches your internal systems.
What happens to the information I enter?
We keep the scan results so we can generate your report. If you ask us to email it, we store your address to send it and to follow up once. We never sell or share your details with anyone. The full detail is in our privacy policy.
What do I get in the emailed report?
The instant result shows your score, your rating, and how many issues we found. The emailed report, sent as a private link, explains every finding in plain English: what it means for you, with a severity rating, across email, website, exposure and brand. The step-by-step fix for each issue comes with the £50 full report, as a PDF you keep.
Found something you want fixed?
Get the £50 full report and you'll have the exact fix for every finding, prioritised and ready to action. A free scan commits you to nothing.
Mainly worried about criminals sending email as you? Our Email Domain Security service takes your domain to full protection and keeps it there, done for you, from £29 a month.