One Platform. Complete Visibility.
See your site the way an attacker does. Six live scanners — Website Scanner, SSL/TLS, MXRecord, Email Header analysis, URL Checks and IP Geo Intelligence — step-by-step fix for every finding.
- ✓ No login ever
- ✓ Nothing stored
- ✓ Results in seconds
- ✓ 100+ checks per scan
- ✓ Live probes, never guesses
Everything You Need to
Secure Your Infrastructure
Web Scan
Run a full Deep Scan of any public website, or pick a single
check from the dropdown — SSL, WAF, headers, ports, WHOIS and more. Auto-tries
both domain.com and www.domain.com.
- ✓ Security grade (A+ to F) + 0–100 score across 31 weighted checks — untested items never count against you, and an equivalent alternative control (e.g. CSP frame-ancestors instead of X-Frame-Options) scores full marks
- ✓ Scans domain.com and www.domain.com, then combines both into one report so nothing is missed
- ✓ SSL certificate — validity, issuer, expiry, SANs + real chain-trust and OCSP stapling
- ✓ TLS cipher grade — forward secrecy, AEAD and weak-cipher detection
- ✓ Protocol support — TLS versions plus HTTP/1.1, HTTP/2 & HTTP/3 (verified, not advertised)
- ✓ WAF/CDN detection — 28 vendor signatures, passive + active probe, on both hosts
- ✓ Security headers — HSTS, CSP, X-Frame-Options, nosniff, Referrer & Permissions-Policy
- ✓ CSP quality grading — scores the policy, not just its presence (flags unsafe-inline)
- ✓ Mixed content — insecure http:// resources on HTTPS pages, split active vs passive
- ✓ Cookie security — Secure, HttpOnly, SameSite + __Host-/__Secure- prefix compliance
- ✓ CORS policy audit — catches wildcard origins combined with credentials
- ✓ Subresource Integrity — third-party scripts loading without an integrity hash
- ✓ Front-end library CVEs — jQuery, Bootstrap, Angular, lodash and more, reported only when a real version is present (never inferred)
- ✓ CVE matching — Apache, Nginx, PHP, IIS with NVD links, labelled confirmed or version-based, and flagged ⚠ KEV when actively exploited. Database auto-refreshes from CISA KEV
- ✓ Sensitive file exposure (.git, .env, backups, phpinfo) + directory listing detection
- ✓ Subdomain enumeration — wordlist + Certificate Transparency & cert SANs, with takeover detection
- ✓ Open port scan — 17 common ports, flags risky admin/database services
- ✓ HTTP methods audit — flags risky verbs (PUT, DELETE, TRACE)
- ✓ DNS records, DNSSEC, CAA, security.txt, robots.txt & sitemap detection
- ✓ CMS & tech stack fingerprinting, internal/external link scan & redirect-chain tracing
- ✓ WHOIS / registration — registrar, dates, nameservers
- ✓ Findings-only "how to fix" guide, shareable report, PDF export & embeddable badge
SSL/TLS Deep Grade
A dedicated, in-depth TLS audit of any HTTPS site — live handshakes test every protocol version and cipher, validate the full certificate chain, and produce an A+ to F TLS grade.
- ✓ Live TLS handshake — real, not header-guessed
- ✓ Protocol matrix — TLS 1.0, 1.1, 1.2 & 1.3 tested individually
- ✓ Flags deprecated TLS 1.0 / 1.1 + browser-compatibility verdict
- ✓ Certificate — issuer, validity, expiry countdown, SANs, serial
- ✓ Hostname match incl. wildcard certificates
- ✓ Key strength (RSA ≥ 2048 / EC ≥ 256) & signature algorithm
- ✓ Negotiated cipher, forward secrecy (ECDHE/DHE) & AEAD
- ✓ Visual certificate-chain trust path (leaf → intermediate → root)
- ✓ Self-signed & incomplete-chain detection
- ✓ Extensions, SHA-1/SHA-256 fingerprints & CT (SCT) presence
- ✓ OCSP / CRL revocation posture & Must-Staple
- ✓ CAA record check (which CAs may issue)
- ✓ HSTS — max-age, includeSubDomains, preload eligibility
- ✓ HTTP security-headers grade (CSP, X-Frame-Options + more)
- ✓ Weighted A+ to F grade with a selective, findings-only fix guide
- ✓ Cipher-strength grade (A+ to F) derived from the negotiated suite, not the certificate alone
- ✓ Per-protocol cipher and bit-strength readout for every TLS version tested
- ✓ Expiry countdown with early-warning thresholds before the certificate lapses
- ✓ Detects certificates issued to the apex but missing www (and vice-versa)
- ✓ >✓ Shareable report, PDF export & embeddable grade badge
MX Record Analysis
Run a full Deep Scan of a domain's email security, or pick a single check from the dropdown — MX servers, SPF, DMARC, DKIM, BIMI, blacklist, DNSSEC, DNS, CNAME, PTR, MTA-STS or TLS-RPT.
- ✓ Deep Scan or 12 individual checks on demand
- ✓ Email provider detection (Google, M365, Proton + more)
- ✓ Email Security Posture Score (severity-weighted, A+ to F)
- ✓ Full MX listing with priority & IP resolution
- ✓ SMTP port check (25, 587, 465) + STARTTLS / TLS support
- ✓ SPF, DMARC & DKIM (parallel selector discovery) analysis
- ✓ MTA-STS policy & TLS-RPT reporting checks
- ✓ CNAME records & PTR (reverse DNS) lookup
- ✓ DNSSEC validation
- ✓ Blacklist check across 15 trusted DNS blocklists (parallel)
- ✓ BIMI brand-indicator lookup
- ✓ Selective "how to fix" guide with copy-paste SPF/DMARC records
- ✓ Fast parallel scanning + shareable report & PDF export
Email Header Analysis
Paste any raw email header and get instant forensic analysis — trace the full delivery route, validate authentication records, and inspect sender and recipient domain security posture.
- ✓ Phishing / spoofing risk score with verdict
- ✓ HELO/EHLO & full SMTP connection details
- ✓ Hop-by-hop routing with colour-coded timing bars
- ✓ SPF, DKIM, DMARC & ARC authentication results
- ✓ SPF / DMARC domain-alignment analysis
- ✓ From / Return-Path / Reply-To mismatch detection
- ✓ Sender & recipient domain DNS + MX records
- ✓ Reverse DNS per relay hop
- ✓ Connecting IP rDNS & TLS analysis
- ✓ X-Originating-IP extraction
- ✓ Spam score & X-header analysis
- ✓ Total delivery-time calculation
- ✓ "How to read & fix" guide with per-issue blog links
Phishing & URL Checker
Paste any suspicious link and get an instant safety verdict before you click. Built for everyone — not just security pros — to spot scams, fake login pages and lookalike domains in seconds.
- ✓ Plain-language safety verdict + 0–100 risk score
- ✓ 35 best-practice phishing tests, pass/fail breakdown
- ✓ Typosquatting & brand-lookalike detection
- ✓ Homograph / punycode (xn--) detection
- ✓ Domain age check — flags freshly registered domains
- ✓ Redirect tracing — reveals the real destination
- ✓ TLS / HTTPS certificate validation
- ✓ Risky TLD, URL-shortener & free-hosting detection
- ✓ "@" trick, numeric-IP, double-extension & encoded-blob detection
- ✓ Reputation check — 24 DNS blocklists + 20 top vendors (Google Safe Browsing, VirusTotal, AbuseIPDB + more)
- ✓ "What to do" guidance + recommended safety reading
IP Geolocation & Network Intel
Your own IPv4 & IPv6 are detected automatically the moment the page loads — then look up any IP or domain to reveal where it's hosted and who owns the network.
- ✓ Auto-detects your IPv4 & IPv6 on page load (no click)
- ✓ Country, region, city, postal & coordinates
- ✓ Map link (OpenStreetMap) + timezone & local currency
- ✓ ISP, organisation & ASN lookup
- ✓ Security intel — proxy / VPN, hosting & mobile-network flags
- ✓ Reverse DNS (PTR) resolution
- ✓ Domain → IP resolution built in
- ✓ Fast, cached lookups with progressive display
- ✓ Recommended reading, shareable link + PDF report
PDF Report Download
After any scan, generate a complete branded PDF report — title page with logo, full results, and a sitealertai.com watermark on every page. Perfect for sharing with clients or your team.
How to Fix Guidance
Every scan includes a selective, findings-only remediation guide — it shows fixes for just the issues detected — with copy-ready config snippets for SSL, security headers, SPF, DMARC, DKIM and more. No login required.
Shareable Result Links
Turn any scan into a private link you can drop into Slack, a ticket or an email. Links re-display the full report and auto-delete after 30 days — with no personal data stored.
Is-This-Link-Safe? Verdict
Paste any suspicious URL and get a clear safety verdict from 35 best-practice phishing tests — typosquatting, homograph tricks, domain age and where the link really lands — plus an on-demand check against 20+ public security blocklists.
A+ to F Security Grade
Every web and email scan distils dozens of checks into one clear letter grade and a 0–100 score — so you instantly know where you stand and what to improve first.
Private & No Login
No account, no sign-up, no tracking. Scans run in real time and nothing about your targets is stored — your reports stay yours, and your own site reveals nothing to scanners.
Start a Scan in 3 Seconds
Enter a Target
Type any domain, IP, or URL. No account needed for web scans.
Scan Runs
Our engine checks SSL, DNS, WAF, ports, headers, CVEs and more in parallel.
Read Your Report
Get a colour-coded security report with a 0–100 score and actionable findings.