← Tools Domain Security Check

Enter a domain and see what it shows the outside world: whether someone can send email pretending to be you, whether any sign-in pages are reachable from the internet, and whether anyone has registered a lookalike version of your name.

Passive external posture check. Reads SPF, DMARC, MX, CAA and DNSSEC over DNS-over-HTTPS, enumerates hostnames from certificate transparency and fingerprints reachable sign-in surfaces, grades HTTP response headers and cookie flags, reads RDAP for registrar lock and expiry, and resolves generated typosquat permutations.

Observation-only external assessment. DoH against cloudflare-dns.com for RFC 7208 SPF qualifier, RFC 7489 DMARC policy and pct, MTA-STS and TLS-RPT presence, and the AD bit for DNSSEC validation. CT issuance data via the certspotter API, wildcards discarded, candidate hosts ranked by label heuristic then fetched once over 443 and matched against product signatures. No SYN scanning, no path enumeration, no proof actions.

This one is not browser-only. Browsers are not permitted to read another site's response headers, so this check cannot run entirely on your machine. The domain you enter is sent to a Teletraan edge worker, which runs the checks and returns the results. The worker stores nothing, logs nothing, and keeps no record of the scan. Everything it reads is data your domain already publishes.
Tool by Teletraan Systems · No data stored by Teletraan · Request a Security & Systems Assessment