Free Infrastructure & Security Tools
Professional-grade tools for checking SSL certificates, IP addresses, DNS records, WHOIS data, and security headers — completely free.
Instantly detect your public IPv4, IPv6, ISP, location, browser, and VPN status.
Validate SSL certificates, check expiry, chain of trust, and TLS grade in seconds.
Audit TLS versions and cipher suites — detect insecure TLS 1.0/1.1 and vulnerable configs.
Instant domain registration data, expiry dates, registrar, and nameserver information via RDAP.
Query DNS records: A, AAAA, MX, TXT, NS, CNAME, SOA. Full resolver output in real time.
Check DNS propagation across multiple global resolvers and see which regions have updated.
Analyse HTTP security headers: HSTS, CSP, X-Frame-Options, Permissions-Policy, and more.
Inspect all raw HTTP response headers, status codes, redirects, and server information.
Check how many days until any domain expires. Get alerts before it lapses.
Verify DNSSEC configuration, validate DNSKEY records, and detect DNS hijacking risks.
Verify DMARC policy, SPF record, and DKIM signing — protect your domain from email spoofing.
Instantly check if any website is online, its HTTP status code, and server response time.
Parse and validate SPF records. Detect misconfigurations, DNS lookup limits, and weak policies.
Look up DKIM public key records, verify key size, and check for common DKIM misconfigurations.
Look up any Autonomous System Number or IP. Find network owner, prefixes, and routing data.
Check IP addresses against threat databases, spam blacklists, and abuse registries.
Look up the PTR record for any IP address. Check FCrDNS for email deliverability.
Scan common TCP ports on any domain or IP. Check HTTP, SSH, database, and mail ports.
Parse and validate Content Security Policy headers. Detect unsafe directives and get recommendations.
Check HTTP Strict Transport Security configuration. Verify max-age, subdomains, and preload status.
Scan pasted code or config for exposed API keys, tokens, and credentials before they reach source control.
Scan package.json or package-lock.json for known CVEs via OSV.dev, with real CVSS scores and a CycloneDX SBOM export.
Scan Terraform, Kubernetes YAML, or a Dockerfile for misconfigurations — public S3 buckets, open security groups, privileged containers.
Calculate your SSL expiry risk score based on days remaining, cert type, auto-renewal, and monitoring.
Simulate your TLS security grade. Select your configuration and see your score update in real time.
Decode a JSON Web Token and inspect its header, payload and expiry. Nothing is sent to a server.
Format, validate and minify JSON, with the exact parse error position when it is invalid.
Encode text to Base64 or decode it back, with full Unicode and URL-safe support.
Generate SHA-1, SHA-256, SHA-384 and SHA-512 digests using the browser Web Crypto API.
Generate cryptographically random version 4 UUIDs, one or a hundred at a time.
Test regular expressions against sample text and see every match, position and capture group.
Read what a cron expression actually does in plain English, with every field explained.
Percent-encode text for a URL or decode it back, with correct UTF-8 handling for accents and emoji.
See the IPv4 addresses a domain resolves to, including every address in a round-robin set.
Check a domain’s IPv6 addresses and whether it is IPv6-ready or IPv4-only.
See what a hostname aliases to, and catch dangling CNAMEs that risk subdomain takeover.
See which mail servers accept email for a domain, sorted by the priority senders actually use.
Check which nameservers are authoritative for a domain and verify a DNS provider migration.
Read a domain’s TXT records exactly as resolvers see them, including its SPF policy.
Build a CVSS v3.1 base score from the eight base metrics, or paste a vector to decode it.
Estimate how long a password would survive three different attackers, and see exactly what weakens it.
Send a real cross-origin request and see whether a server reflects arbitrary origins or exposes credentials.
Check every cookie a site sets for Secure, HttpOnly, SameSite and the browser-enforced name prefixes.
Trace every hop a URL takes and catch chains that end on HTTP, downgrade mid-way, or loop.
Parse a site’s crawler rules the way a crawler does, and spot sensitive paths advertised in a public file.
Find and validate an XML sitemap, including any declared in robots.txt, and check what it contains.
Detect the server, CMS, framework, CDN and analytics behind a site — and what version it gives away.
MX, SPF, DKIM, DMARC, MTA-STS, TLS-RPT and BIMI in one check, scored by what each record prevents.
Validate a domain’s SMTP TLS policy, including whether every MX host is actually covered by it.
Check where a domain receives SMTP TLS failure reports — the visibility MTA-STS enforcement depends on.
Check a BIMI record, its logo and VMC — and whether DMARC is enforcing, which is what gates it.
Check a domain or IP against the major DNS blocklists and see which lists have it, and why.
Discover subdomains from public Certificate Transparency logs — real certificates, not a wordlist.
Search public CT logs for every certificate issued for a domain, and spot ones you did not request.
Paste a PEM certificate and read every field and extension inside it, decoded in your browser.
Compute SHA-256, SHA-1 and SHA-512 fingerprints and compare against the value you expect.
Find the missing intermediate that works in browsers and breaks curl, plus expiry anywhere in the chain.
Check whether a server staples its revocation status during the handshake, and find its OCSP responder.
Look up a CVE or GHSA identifier and see the packages and version ranges it actually affects.
Read a CycloneDX or SPDX bill of materials: components, versions and licences, entirely in your browser.
Check a Dockerfile for root users, secrets baked into layers, unpinned images and exposed ports.
See what an API endpoint tells an anonymous caller: whether it answers, its headers, CORS policy and published specifications.
Review an OpenAPI or Swagger specification for unauthenticated writes, secrets in query strings and weak auth schemes.
Check whether a GraphQL endpoint hands out its schema through introspection or field suggestions.
Find when a domain was first registered, how old it is, and what its registry status codes mean.
See which network owns an address: the ASN, the announcing organisation, the prefix and reverse DNS.
Look up an address’s reverse DNS and network owner, and verify which of your domains resolve to it.
Automate your infrastructure monitoring
Stop checking manually. Get automated SSL, domain, and DNS alerts before things break.