Checks anyone can run. Nothing leaves your browser.
Seven checks the operator runs on day zero of every engagement, open to everyone: web, mail, brand, credentials, smart contracts, prompts and AI agents. No account, no card, no quota, no storage. Each tool talks directly from your browser to a public source and shows you the answer as it came back.
Security headers grade
HSTS, CSP, cookies, referrer and framing policy graded A to F by MDN HTTP Observatory, with the full breakdown and the fixes one click away.
Email and DNS posture
SPF policy, DMARC enforcement, DKIM selectors, MX, DNSSEC and CAA in one verdict. The five controls that decide whether your domain can be spoofed.
Typosquat finder
Generates look-alike domains for your brand, including keyboard neighbours, homoglyphs, hyphenation, suffixes and TLD swaps, then resolves each one to see which are already registered.
Pwned password check
Is this password in a known breach? SHA-1 is computed locally and only its first five characters are sent, so the password itself never leaves this page.
Contract X-ray
Paste an Ethereum mainnet address. Reads the bytecode and storage directly from public nodes: verified source, ERC-1967 proxy and admin, owner, pause state, dangerous opcodes and every function selector, with the privileged ones called out.
Hidden-instruction scanner
Paste a prompt, a document, an email or a web page's text. Finds invisible Unicode tags, zero-width and bidirectional controls, homoglyphs, prompt-injection and tool-poisoning phrases, and leaked secrets. Zero network.
MCP tool-poisoning scanner
Paste the JSON an MCP server returns for tools/list. Flags hidden markers, concealment from the user, sensitive file references, tool shadowing, outbound URLs and exfiltration language in tool descriptions. Static, never connects.
Are these tools really free?
Yes. No account, no card, no quota on this page. They exist because these are the first checks any serious audit starts with, and hiding them would be silly.
What do you store?
Nothing. There is no backend. Each check runs in your browser against a public source: MDN HTTP Observatory, Cloudflare DNS over HTTPS and Have I Been Pwned. Their own retention rules apply to the request they receive.
Can I check any domain?
Only domains you own or are authorised to assess. The checks are passive DNS and HTTP lookups, but authorisation is still the rule of this house.
What does a bad score mean?
That the control is missing or not enforced, not that you have been breached. It is the difference between an open door and an intruder. The full snapshot from Block The Chain covers what is behind the door.
Why is my DKIM not found?
DKIM records live under a selector name that only your mail provider knows. The tool tries fourteen common selectors. If yours is custom, the record can exist and still not show here.
Sources: MDN HTTP Observatory (Mozilla, MPL 2.0 project) · Cloudflare 1.1.1.1 DNS over HTTPS · Have I Been Pwned Pwned Passwords (CC BY 4.0) · Ethereum public RPC (publicnode, 1rpc, dRPC) · Sourcify · 4byte signature database. This page uses public APIs and is not endorsed by their operators.