Secure Your Server

What this is, in plain terms

A free security scanner that tells you exactly what it looked at

Secure Your Server runs two independent checks against infrastructure you control: a domain security scan and an email delivery test. Both are free, permanently, with no account, no paywall and no tracking. This page explains what the project is, why it exists, and lists every single check it runs so nothing is a surprise.

Free forever, no accountNo tracking, no third-party cookiesFull list of every check below

Why this exists

Most tools that check TLS configuration, mail authentication, HTTP headers or open ports are scattered across a dozen separate services, several of which are commercial, rate-limited, or ask for an account before showing a full result. Secure Your Server puts the checks operators actually need before an audit, a client handover or a "why did this email land in spam" investigation in one place, with a single grade per category and, once you prove you control the target, every individual finding plus concrete fix guidance instead of a vague pass/fail.

How a scan works

Submit a domain

Enter a domain you control. Bare IP addresses and email addresses cannot be scanned; ownership can only be proven for domains.

Prove you control it, before anything runs

Starting a scan requires proof of ownership up front (a DNS TXT record or a well-known file). Without it, no scan runs and nothing gets stored, not even a grade.

Eight checks run, the full report is yours

DNS, email authentication, TLS/SSL, SSH, ports, HTTP security headers, WHOIS and PGP/WKD all run, and you get every individual finding plus fix guidance immediately, valid for 365 days. Anyone who later finds this domain on the public leaderboard without verifying it themselves only ever sees the category grades.

Domain security scan: every check, in detail

Eight categories, each scored independently and combined into one overall grade. Nothing here is guessed: every finding links back to the RFC, vendor guideline or CVE it is based on inside the report itself.

DNS

Resolution, redundancy and zone hygiene, including a real zone transfer attempt.

  • A/AAAA resolution and IPv6 (AAAA) reachability
  • Nameserver count and redundancy (RFC 2182 recommends at least two)
  • DNSSEC presence
  • CAA records: which certificate authorities may issue for the domain, and whether an iodef reporting address is set
  • SOA timer sanity (refresh/retry/expire values)
  • An actual AXFR zone transfer attempt against every authoritative nameserver, flagged if any of them hands out the full zone to an unauthenticated request
  • Wildcard DNS detection, which also protects other checks (like DKIM selector discovery) from false positives

Email authentication (SPF / DKIM / DMARC / MTA-STS)

Whether your domain’s outgoing mail can be forged, and whether it lands in spam.

  • SPF record presence, syntax, the 10-lookup DNS limit, and whether it ends in a hard fail (-all) or a weaker soft fail (~all)
  • DKIM key discovery via common selectors
  • DMARC record presence, policy strength (none/quarantine/reject), alignment mode and aggregate reporting (rua)
  • MTA-STS policy reachability (informational, no score penalty)
  • The mail server IPs checked against four public DNSBLs (spam blacklists) used in real-world mail filtering

TLS/SSL

Full protocol, cipher and certificate analysis via testssl.sh, not just a pass/fail on HTTPS.

  • Every protocol version from SSLv2 to TLS 1.3: which are offered, which should be disabled
  • The complete cipher suite list per protocol, weakest first, with testssl’s own OK/LOW/MEDIUM/HIGH rating per suite
  • Key exchange and forward secrecy
  • Certificate details: common name, SAN, validity window, key size, signature algorithm, issuer, chain of trust, and a realistic expiry warning (only ≤7 days is treated as urgent, since 90-day Let’s Encrypt certificates renewing at day 40 are completely normal)
  • Known named vulnerabilities: Heartbleed, ROBOT, DROWN, FREAK, Logjam/weak DH, SWEET32, BREACH, Ticketbleed, POODLE, BEAST, LUCKY13, CRIME
  • Simulated client compatibility (which browsers/clients can actually connect)
  • A Certificate Transparency log lookup (crt.sh) showing recently issued certificates for the domain, purely informational

SSH

Full ssh-audit of the server banner and every algorithm it offers.

  • Server banner and software version
  • Every key exchange, host key, encryption cipher and MAC algorithm offered, each individually rated
  • Known CVEs matched against the detected SSH software version, linked to their NVD entry
  • Compared against Mozilla’s modern OpenSSH hardening guidelines

Ports & firewall

What is reachable from the open internet, with service-specific hardening tips.

  • The top 20 most common ports checked for anyone; a full top-1000 scan with service and version detection unlocks after verification
  • Over two dozen ports flagged as risk signals when exposed (databases, cache servers, management interfaces, legacy protocols like Telnet and FTP), each with its own concrete first fix instead of a generic "close your firewall"
  • A warning when an unusually high number of ports are open at once

HTTP security headers

Every header a modern browser understands, plus the well-known discovery files.

  • HTTPS enforcement and automatic HTTP-to-HTTPS redirect (following up to 10 redirect hops, reporting the final address actually tested)
  • Content-Security-Policy, including unsafe-inline/unsafe-eval and wildcard script-src detection
  • HSTS: presence, max-age length, includeSubDomains and preload directives
  • X-Content-Type-Options, X-Frame-Options, Referrer-Policy value validation (not just presence)
  • Cross-Origin-Opener-Policy, Cross-Origin-Embedder-Policy, Cross-Origin-Resource-Policy
  • CORS wildcard combined with credentialed cookies
  • security.txt per RFC 9116, with real field and expiry-date validation, not just a presence check
  • llms.txt, robots.txt and humans.txt as informational checks with no score penalty either way, since none of them are established standards yet
  • All header checks are skipped with a neutral "not applicable" grade, never a fail, when a target has no web server on port 80/443 at all

WHOIS

Registration status and the operational risk of an expiring domain.

  • Domain expiry date, with escalating warnings as it approaches
  • Registry status codes: registration hold states and missing transfer/update locks
  • Nameserver count as declared in the registry itself

PGP / WKD

Whether encrypted mail to this domain is realistically possible.

  • Public key discovery via Web Key Directory (WKD) and keyservers
  • Key length and age
  • Expiry and revocation status

How the grades are calculated

Every category gets its own score from 0 to 100, mapped to a letter grade (A+ at 97 and above, down to F below 50), the same scale style used by well-known SSL testing tools. The overall grade is a plain average of every category that actually completed. Categories that don’t apply to a target (for example header checks on a domain with no web server) are excluded entirely rather than counted as a fail, so they can’t drag an otherwise solid domain down artificially.

Email delivery test: what gets checked

A separate tool from the domain scan, because a domain’s DNS records only tell half the story. This test looks at a real message as it actually arrives.

  • A temporary, single-use receiving address, valid for 15 minutes and usable exactly once
  • SPF, DKIM and DMARC authentication results as evaluated on the actual message received, not just the DNS records in isolation
  • The TLS connection the sending server used for delivery
  • Reverse DNS (rDNS/PTR) of the sending mail server
  • Spam-relevant signals from the message itself
  • The full raw email headers, available to you alone via a private one-time link

Privacy, by construction

  • No account, no login and no tracking scripts anywhere on the site
  • Exactly one cookie exists on the entire service, set only after you verify a domain, described in full in the cookie notice
  • Detailed findings for a domain are only ever visible to whoever proved ownership of it; everyone else only ever sees the grades
  • The test mailbox for the mail delivery test is wiped immediately after each message is processed, plus a 24-hour safety sweep
  • You can exclude any domain you own from the public leaderboard entirely
Built by chrislo.de

Made at chrislo.de, Studio für freie Technik

Secure Your Server is built and operated by chrislo.de, Christin Löhner’s studio for free technology, digital sovereignty and IT security. The same conviction behind that studio shapes this tool: security tooling that matters shouldn’t sit behind a paywall, an account wall or a vendor relationship. Everyone should be able to check their own infrastructure for free, understand exactly what was tested, and get real, actionable guidance instead of a marketing-grade traffic light.

Visit chrislo.de →

See where your own domain actually stands

Every check on this page runs the moment you submit a domain. No signup, no waiting list.