Terms of use

Secure Your Server (secure-your-server.com / sichere-deinen-server.de) is a free, non-commercial security scanning tool. By using it, you agree to the following:

1. Only scan what you're authorized to scan

You may only submit domains that you own, operate, or are otherwise explicitly authorized to test. (Bare IP addresses and email addresses currently can't be submitted at all, because we have no reliable way to verify you actually control them.) Scanning third-party infrastructure without authorization may be illegal in your jurisdiction. That responsibility is yours, not ours.

2. Only test mailboxes you're authorized to test

The mail delivery test works differently but the same rule applies: by requesting a temporary test address, you confirm you will only send a message to it from a mailbox you own or are otherwise explicitly authorized to test. We fetch, parse and immediately delete the message you send (see our privacy policy for exactly what's processed and for how long); results are private, reachable only via your one-time result link, and are never published or added to the leaderboard.

3. What the scanner actually does

Most checks (DNS, SPF/DKIM/DMARC, TLS/SSL handshake analysis, SSH banner/algorithm negotiation, HTTP security headers, WHOIS, PGP/WKD lookup) are passive: the same kind of standard protocol negotiation any browser, mail client, or search engine performs routinely.

A full, multi-port scan (nmap, up to 1000 ports) is active and only unlocked after you prove control over the target domain (DNS TXT record or well-known file). Without verification, only the top 20 most common ports are checked.

Without that proof, every check only shows a grade (A+ to F) per category: no individual findings, no descriptions, no fix guidance. The full report only unlocks after you've proven you control the domain. This prevents anyone from pulling detailed security findings about a system they have no authorization over.

4. Rate limiting & abuse prevention

Requests (domain scans, verification checks, and mail delivery test addresses) are rate-limited per IP address. For domain scans specifically, we additionally log the scanned target, the requesting IP address, and a timestamp for up to 30 days, solely to investigate abuse reports. See our privacy policy. If you believe this service was used to scan your infrastructure without authorization, see our abuse contact page.

5. No warranty

This tool is provided free of charge, without any warranty, and on a best-effort basis. Results are a snapshot in time and do not constitute a professional security audit. We are not liable for decisions made based on these results, nor for downtime or side effects the scans may cause on your own infrastructure.

6. Free, forever

This service will never require an account, a subscription, or payment. No third-party trackers, no ads.

This is a plain-language summary, not a formal legal contract. See theimprint for the operator's contact details.