Is your website already compromised?
Enter your domain. In about 20 seconds we check 25+ public signals: malware and spam injection, hidden redirects, SSL/TLS, security headers, exposed software versions and email spoofing protection.
- Passive and non-intrusive
- No sign-up
- Results in seconds
Scanning
- Resolving domain and DNS
- Checking the SSL/TLS certificate
- Analysing HTTP security headers
- Searching for malware and spam injection
- Comparing crawler and visitor view (cloaking)
- Checking email spoofing protection
Scan ID:
Detailed findings
The exact location of each issue, the evidence and the step-by-step fix are in your detailed report.
Get your detailed report — free
We send the full report with every finding, where it is and how to fix it. For security reasons the details are only shared with the owner of the website.
What the free check covers
Everything is read from the outside, exactly as a visitor or search engine sees your site.
Malware and spam injection
Casino, pharma and Japanese SEO spam, injected links and obfuscated scripts that hacked sites typically carry.
Hidden redirects and cloaking
Whether visitors or search engines are silently sent somewhere else — the classic sign of a compromised CMS.
SSL / TLS
Certificate validity and expiry, and whether every visitor is moved to an encrypted connection.
Security headers
HSTS, Content Security Policy, clickjacking and MIME protection, referrer and permissions policies.
Software exposure
Server, PHP and CMS versions your site reveals publicly, including software that no longer receives security fixes.
Email spoofing protection
SPF and DMARC records that stop criminals sending email in your company's name.
Safe by design
The check only reads what any visitor can already see. No login attempts, no exploitation, no load on your server.
Already hacked?
Redirects to casino or pharma sites, Google warnings, strange pages in search results? We clean infected sites and close the hole they came through.