Safe by design
URL tools check one public URL, block private/internal targets, use short timeouts, and avoid response-body proxying. They are built for diagnostics, not scanning.
Review public website-facing and domain-facing signals such as domain intelligence, response headers, security headers, robots.txt crawler directives, XML sitemaps, canonical/noindex tags, AI crawler access rules, llms.txt hints, meta title and description tags, heading structure, Open Graph metadata, structured data, SSL certificate records, redirect chains, DNS, and certificate-authority DNS policy. Start with Domain Intelligence or the combined Domain Security Scan, then open focused tools when a signal needs review.
Run DNS inventory, RDAP-safe registration context, IP/ASN hints, PTR, CAA, DNSSEC, TXT summaries, and provider hints together.
Website Exposure ScannerRun HTTPS, redirects, security headers, HSTS, DNS records, IPv6, mixed content, and basic CDN/origin signals together.
AI/Search Visibility ScannerCheck robots.txt, noindex, canonical, sitemap, server-rendered content, llms.txt, and AI crawler access signals.
Domain Security ScanRun SSL, headers, CAA, SPF, DMARC, robots.txt, sitemap, canonical, Open Graph, and schema checks together.
HTTP Headers CheckerView selected response headers for one public URL.
Security Headers CheckerCheck common security-related header presence.
Redirect CheckerFollow a limited redirect chain with status codes.
HTTP Latency TestMeasure constrained HTTP request timing.
SSL Certificate CheckerReview certificate transparency issuer, expiry, SAN, and match signals.
Robots.txt CheckerParse crawler directives, sitemap declarations, and common SEO signals.
Sitemap CheckerValidate XML sitemap structure, sampled child sitemaps, and URL signals.
Canonical / Noindex CheckerInspect canonical tags, meta robots, and X-Robots-Tag headers for one public URL.
Meta Title / Description CheckerInspect title tags, meta descriptions, duplicate metadata, and snippet preview signals.
HTML Heading / Content Structure CheckerInspect heading hierarchy, skipped levels, duplicates, and content structure signals.
Open Graph / Social Preview CheckerInspect social preview metadata, Twitter/X Card fields, and preview conflicts for one public URL.
Structured Data / JSON-LD ValidatorCheck JSON-LD blocks, schema.org types, malformed structured data, and basic schema findings for one public URL.
CAA LookupCheck certificate authority DNS policy records.
DNS LookupReview public DNS records for a domain.
WHOIS / RDAP LookupReview public registry context for domains, IP addresses, and ASNs.
URL tools check one public URL, block private/internal targets, use short timeouts, and avoid response-body proxying. They are built for diagnostics, not scanning.
No. They check selected public signals only.
No. Internal and private targets are blocked.
Port scanning carries higher abuse risk and remains deferred.
Check my website/domain
Public DNS, HTTP, HTTPS, certificate, redirect, header, IP/ASN, or domain configuration signals.
Limits
It cannot perform credentialed vulnerability testing, scan private hosts, bypass access controls, or certify complete security.
Read results
Treat results as review signals for this browser/session or public target. Re-test after one change, then use Safe Copy or notes that avoid raw identifiers.