A free security scanner that tells you exactly what it looked at
Secure Your Server runs two independent checks against infrastructure you control: a domain security scan and an email delivery test. Both are free, permanently, with no account, no paywall and no tracking. This page explains what the project is, why it exists, and lists every single check it runs so nothing is a surprise.
Free forever, no accountNo tracking, no third-party cookiesFull list of every check below
Most tools that check TLS configuration, mail authentication, HTTP headers or open ports are scattered across a dozen separate services, several of which are commercial, rate-limited, or ask for an account before showing a full result. Secure Your Server puts the checks operators actually need before an audit, a client handover or a "why did this email land in spam" investigation in one place, with a single grade per category and, once you prove you control the target, every individual finding plus concrete fix guidance instead of a vague pass/fail.
How a scan works
1
Submit a domain
Enter a domain you control. Bare IP addresses and email addresses cannot be scanned; ownership can only be proven for domains.
2
Prove you control it, before anything runs
Starting a scan requires proof of ownership up front (a DNS TXT record or a well-known file). Without it, no scan runs and nothing gets stored, not even a grade.
3
Eight checks run, the full report is yours
DNS, email authentication, TLS/SSL, SSH, ports, HTTP security headers, WHOIS and PGP/WKD all run, and you get every individual finding plus fix guidance immediately, valid for 365 days. Anyone who later finds this domain on the public leaderboard without verifying it themselves only ever sees the category grades.
Domain security scan: every check, in detail
Eight categories, each scored independently and combined into one overall grade. Nothing here is guessed: every finding links back to the RFC, vendor guideline or CVE it is based on inside the report itself.
◈
DNS
Resolution, redundancy and zone hygiene, including a real zone transfer attempt.
A/AAAA resolution and IPv6 (AAAA) reachability
Nameserver count and redundancy (RFC 2182 recommends at least two)
DNSSEC presence
CAA records: which certificate authorities may issue for the domain, and whether an iodef reporting address is set
SOA timer sanity (refresh/retry/expire values)
An actual AXFR zone transfer attempt against every authoritative nameserver, flagged if any of them hands out the full zone to an unauthenticated request
Wildcard DNS detection, which also protects other checks (like DKIM selector discovery) from false positives
Whether your domain’s outgoing mail can be forged, and whether it lands in spam.
SPF record presence, syntax, the 10-lookup DNS limit, and whether it ends in a hard fail (-all) or a weaker soft fail (~all)
DKIM key discovery via common selectors
DMARC record presence, policy strength (none/quarantine/reject), alignment mode and aggregate reporting (rua)
MTA-STS policy reachability (informational, no score penalty)
The mail server IPs checked against four public DNSBLs (spam blacklists) used in real-world mail filtering
◐
TLS/SSL
Full protocol, cipher and certificate analysis via testssl.sh, not just a pass/fail on HTTPS.
Every protocol version from SSLv2 to TLS 1.3: which are offered, which should be disabled
The complete cipher suite list per protocol, weakest first, with testssl’s own OK/LOW/MEDIUM/HIGH rating per suite
Key exchange and forward secrecy
Certificate details: common name, SAN, validity window, key size, signature algorithm, issuer, chain of trust, and a realistic expiry warning (only ≤7 days is treated as urgent, since 90-day Let’s Encrypt certificates renewing at day 40 are completely normal)
Known named vulnerabilities: Heartbleed, ROBOT, DROWN, FREAK, Logjam/weak DH, SWEET32, BREACH, Ticketbleed, POODLE, BEAST, LUCKY13, CRIME
Simulated client compatibility (which browsers/clients can actually connect)
A Certificate Transparency log lookup (crt.sh) showing recently issued certificates for the domain, purely informational
▣
SSH
Full ssh-audit of the server banner and every algorithm it offers.
Server banner and software version
Every key exchange, host key, encryption cipher and MAC algorithm offered, each individually rated
Known CVEs matched against the detected SSH software version, linked to their NVD entry
Compared against Mozilla’s modern OpenSSH hardening guidelines
▤
Ports & firewall
What is reachable from the open internet, with service-specific hardening tips.
The top 20 most common ports checked for anyone; a full top-1000 scan with service and version detection unlocks after verification
Over two dozen ports flagged as risk signals when exposed (databases, cache servers, management interfaces, legacy protocols like Telnet and FTP), each with its own concrete first fix instead of a generic "close your firewall"
A warning when an unusually high number of ports are open at once
◫
HTTP security headers
Every header a modern browser understands, plus the well-known discovery files.
HTTPS enforcement and automatic HTTP-to-HTTPS redirect (following up to 10 redirect hops, reporting the final address actually tested)
Content-Security-Policy, including unsafe-inline/unsafe-eval and wildcard script-src detection
HSTS: presence, max-age length, includeSubDomains and preload directives
X-Content-Type-Options, X-Frame-Options, Referrer-Policy value validation (not just presence)
security.txt per RFC 9116, with real field and expiry-date validation, not just a presence check
llms.txt, robots.txt and humans.txt as informational checks with no score penalty either way, since none of them are established standards yet
All header checks are skipped with a neutral "not applicable" grade, never a fail, when a target has no web server on port 80/443 at all
◔
WHOIS
Registration status and the operational risk of an expiring domain.
Domain expiry date, with escalating warnings as it approaches
Registry status codes: registration hold states and missing transfer/update locks
Nameserver count as declared in the registry itself
✦
PGP / WKD
Whether encrypted mail to this domain is realistically possible.
Public key discovery via Web Key Directory (WKD) and keyservers
Key length and age
Expiry and revocation status
How the grades are calculated
Every category gets its own score from 0 to 100, mapped to a letter grade (A+ at 97 and above, down to F below 50), the same scale style used by well-known SSL testing tools. The overall grade is a plain average of every category that actually completed. Categories that don’t apply to a target (for example header checks on a domain with no web server) are excluded entirely rather than counted as a fail, so they can’t drag an otherwise solid domain down artificially.
Email delivery test: what gets checked
A separate tool from the domain scan, because a domain’s DNS records only tell half the story. This test looks at a real message as it actually arrives.
A temporary, single-use receiving address, valid for 15 minutes and usable exactly once
SPF, DKIM and DMARC authentication results as evaluated on the actual message received, not just the DNS records in isolation
The TLS connection the sending server used for delivery
Reverse DNS (rDNS/PTR) of the sending mail server
Spam-relevant signals from the message itself
The full raw email headers, available to you alone via a private one-time link
Privacy, by construction
No account, no login and no tracking scripts anywhere on the site
Exactly one cookie exists on the entire service, set only after you verify a domain, described in full in the cookie notice
Detailed findings for a domain are only ever visible to whoever proved ownership of it; everyone else only ever sees the grades
The test mailbox for the mail delivery test is wiped immediately after each message is processed, plus a 24-hour safety sweep
You can exclude any domain you own from the public leaderboard entirely
Built by chrislo.de
Made at chrislo.de, Studio für freie Technik
Secure Your Server is built and operated by chrislo.de, Christin Löhner’s studio for free technology, digital sovereignty and IT security. The same conviction behind that studio shapes this tool: security tooling that matters shouldn’t sit behind a paywall, an account wall or a vendor relationship. Everyone should be able to check their own infrastructure for free, understand exactly what was tested, and get real, actionable guidance instead of a marketing-grade traffic light.
This site uses exactly one cookie, and only if you verify a domain. See what it does below.
Cookie notice
This service uses exactly one cookie, described below. No third-party cookies, no tracking, no advertising. Ever.
Domain-verification cookieEssential
Set only after you successfully prove control over a domain (DNS TXT record or well-known file) to unlock its full scan report. Cookie name: sys_owner_<domain>. HttpOnly (unreadable by any script), Secure, SameSite=Lax, sent only to this site. Purpose: on later visits, it proves that you are the person who verified this exact domain, so only you (not anyone who finds the domain on the public leaderboard) see the full report with individual findings and fix guidance. Never used for tracking or analytics, and never shared with third parties. Expires after 365 days, matching the verification period itself. This cookie is essential to the verification feature and is only ever set when you actively use it. It is never set on a normal visit.