Free tool · Exposure checks

What can an attacker see about your domain right now?

A free domain security check: whether anyone can send mail as your domain, what its SSL/TLS estate is serving, and how its web applications are configured — three of the vectors behind a Bitsight rating, graded live across every subdomain we can find.

Check your domain

In short
Three of the ten risk vectors behind a security rating can be read from outside in under a minute: email authentication from public DNS, TLS from a handshake with each host, and web application security from one homepage request. All three are configuration, not architecture, so they are the cheapest findings to clear. The other seven need an observation window and an attributed estate, which the Rating Report supplies.

Check your domain

Enter the domain and a work email address on it. Three checks run at once: the DNS records that decide whether anyone can send mail as you, resolved in your own browser; a TLS handshake with every live host we can find under the domain; and one request for each host’s homepage, read for the web application settings a rating assesses. The last two come from our servers. All three finish in under a minute on most estates.

Three live checks against a domain you own. Email authentication resolves public DNS from your browser. TLS and web application security connect from our servers — a handshake and one homepage request per host, the only way to read a certificate or a response header.

A worked example, below. This is the reading for the specimen domain, so the page answers before you enter anything. Run the check above to replace it with your own.

3 of 10risk vectors read — worked example. 11 exposures and 15 gaps found.
  • DEmail authenticationp=none tells receiving servers to take no action on mail that fails. It is the correct place to start — it turns on the reports you need before enforcing — but it is a monitoring configuration, and a domain left here is as forgeable as one with no record at all. This is where most domains stop.7 records read
  • FTLS and certificates9 findings a browser would warn about, across 6 live hosts.6 hosts probed
  • FWeb application security1 finding an attacker can use today, across 4 web hosts.4 hosts read, 1 blocked, 1 sent elsewhere
  • —Seven more vectorsBotnet infections · Spam propagation · Malware servers · Unsolicited communications · Critical vulnerability management · Open ports · DNSSECnot read here

The letters are ours, not Bitsight’s. A Bitsight vector grade is a percentile against every company it rates, normalised for size, and cannot be derived from one domain. What these encode is the basis printed beside each one.

These three are configuration rather than architecture, which makes them the cheapest findings to clear. The other seven need an observation window and an attributed estate — which is what the Cyber Risk Rating Report supplies, scored 250–900 and benchmarked against your sector.

Get my full rating →

Why the email has to match

This is the only tool here that will not answer for any input, and the reason is worth stating plainly. Every other page in this set computes something it already knows: the registers, the thresholds and the clocks are on the page, and the calculator is a convenience. This one opens connections to your servers from ours. That is the single thing on this site that spends somebody else’s resources, and an anonymous scanning endpoint is worth more to an abuser than it is to a visitor.

So the address has to sit on the domain being scanned, or beneath it — you@yourcompany.in may scan yourcompany.in and mail.yourcompany.in, and nothing else. Containment rather than a comparison of registrable domains, because getting the latter wrong fails in the dangerous direction: India alone has co.in, ac.in, gov.in and several more, and a suffix list that misses one turns a match on your domain into a match on everybody’s.

What the web application read covers

Web Application Security became a rated vector in Bitsight’s algorithm update of July 2025, taking the weight Web Application Headers used to carry. Bitsight assesses each application as loaded in a browser, for five things: components with known vulnerabilities, broken authentication, sensitive data exposure, defences against cross-site scripting, and misconfiguration such as cookie flags and HSTS.

This reads what two plain requests can show — port 80, and the homepage over HTTPS — without running the page:

  • Misconfiguration. Whether port 80 sends visitors to HTTPS, whether HSTS is set for at least a year, and whether cookies carry Secure and SameSite.
  • Cross-site scripting defences. The Content Security Policy, read with CSP Evaluator, the open-source library behind csp-evaluator.withgoogle.com. Only its high-severity findings count: a policy that is report-only, sets no script source, or allows a host known to serve JSONP is reported as no defence.
  • Components with known vulnerabilities. Library releases named in the page’s script URLs — jQuery, jQuery UI, Bootstrap, AngularJS, Lodash, Moment.js — against the published advisories for each.
  • Data exposure and authentication, from outside. Scripts loaded over plain HTTP on an HTTPS page, a server banner naming its version, and a password field travelling in the clear.

What it does not do matters as much. No path is probed, nothing is submitted, and no script runs, so a library bundled into the site’s own code is not seen — the result says so rather than reporting a clean page. X-Frame-Options and the other headers that made up the retired vector are not graded, because they no longer move a rating. Requests identify themselves as BitScore. Large estates often sit behind a bot-management layer that answers our servers with a challenge; those hosts are listed as blocked and left out of the grade, never counted as a pass.

Three vectors out of ten

A Bitsight Security Rating is calculated from ten risk vectors. This reads three of them, and the result says so where it shows the grades rather than in a footnote. The three it reads are the three that can be observed from outside without a window of history: a DNS lookup answers the first, a handshake the second, and a homepage request the third.

The seven it does not read:

  • Botnet infections
  • Spam propagation
  • Malware servers
  • Unsolicited communications
  • Critical vulnerability management
  • Open ports
  • DNSSEC

Those need an attributed estate and an observation window — which host belongs to which company, and what it was doing over months rather than at the moment of a probe. Neither is derivable from one domain by us or by anyone else, and a free tool claiming otherwise is claiming something it cannot have.

The letter grades here are this tool’s own. A Bitsight vector grade is a percentile against every company Bitsight rates, normalised for size. What these encode is printed beside each one, so the arithmetic is yours to check.

What to do with the result

All three vectors here are configuration rather than architecture, which is what makes them worth clearing first. They are also all covered by Dynamic Remediation — Bitsight’s on-demand rescan — so credit for a fix arrives on request rather than at the next observation.

  • Email authentication. Publish the transport records first, because they break nothing, and move DMARC to enforcement last, because moving it before the reports are clean is what breaks invoicing on a Monday morning. The email spoofing check gives the record to publish for each finding in that order.
  • TLS. Protocol versions first — setting a minimum of TLS 1.2 on one host usually clears three findings at once. Certificates second, because each is its own reissue and they parallelise. The SSL estate check lists every affected host.
  • Web application security. The port-80 redirect and HSTS first — one server setting each, and often one load balancer for every host behind it. Cookie flags second. The Content Security Policy third, because it should run report-only for a few weeks before it is enforced. Library upgrades last: each one is a regression test.
  • Then the other seven. The Cyber Risk Rating Report is where they come from, with the rating itself and the benchmark against your industry. It is complimentary and needs no access to your systems.
Every instrument cited here was verified against the issuing regulator's own notification on .

Questions this page answers

How do I check my domain’s security rating?
Two steps. This check reads three of the ten vectors live — email authentication, SSL/TLS and web application security — in under a minute, which shows the configuration findings that are cheapest to clear. The rating itself, on Bitsight’s 250–900 scale and benchmarked against your industry, comes from the complimentary Cyber Risk Rating Report: all ten vectors, ransomware and breach likelihood, in 45 minutes for listed entities and up to 48 hours for everyone else, with no access to your systems.
What replaced Web Application Headers in the Bitsight rating?
Web Application Security. Bitsight’s ratings algorithm update of 10 July 2025 made it rating-impacting and gave it the 5% weight Web Application Headers had carried. Headers is now informational and no longer moves a rating. The new vector assesses each application as a browser loads it: components with known vulnerabilities, broken authentication, sensitive data exposure, defences against cross-site scripting such as a Content Security Policy, and misconfiguration such as HSTS and cookie flags. A headers grade alone no longer describes it.
Why do I have to use an email address on the domain I am checking?
Because the scan is not a lookup — it opens connections to your servers from ours, which is the one thing on this site that costs a third party something. Requiring an address on the domain being scanned, or beneath it, means the tool only ever points at an estate the person asking can show they belong to. Every other tool here answers for any input, because the answer is a fact the page already holds.
Our group sends email from a different domain to the website. Can we still use it?
Not through this tool, and that is a deliberate limit rather than an oversight. Containment is what makes the scan authenticated, and loosening the comparison to cover group domains would mean accepting an assertion instead of a demonstration. Request the Cyber Risk Rating Report instead — it covers the whole attributed estate, needs no address match, and reads all ten vectors rather than three.
How much of a security rating do these three checks cover?
Three vectors out of ten, and they are the three cheapest to fix. Email authentication, TLS configuration and web application security are all settings rather than architecture, and all are covered by Bitsight’s Dynamic Remediation, which means credit for a fix arrives on request instead of at the next observation. The other seven — botnet infections, spam propagation, malware servers, unsolicited communications, critical vulnerability management, open ports and DNSSEC — need an observation window and an attributed estate.
Is the web application read the same as Bitsight’s?
It covers part of it. Bitsight assesses each application as loaded in a browser; this reads the response headers and page source from two requests without running anything. HSTS, the port-80 redirect, cookie flags and the Content Security Policy — read with CSP Evaluator, the open-source library behind csp-evaluator.withgoogle.com — are read well. Library versions are read from script URLs, so a library bundled into the site’s own code is missed, and the result says so. Hosts that answer our servers with a bot challenge are listed as blocked and left out of the grade.
Are the letter grades the same as Bitsight’s?
No, and the result says so where it shows them. A Bitsight vector grade is a percentile against every company Bitsight rates, normalised for size. Nothing derived from one domain can be that. The letters here encode what was found on your estate, with the basis printed next to each one so the arithmetic is yours to check.
What does the scan actually do to our servers?
The email half resolves public DNS records from your browser against Google and Cloudflare, and never reaches us. The TLS half looks for subdomains in the Certificate Transparency logs, keeps the ones that resolve, and completes a TLS handshake with each — the same exchange a browser performs before loading a page. The web application half requests each host’s homepage once over port 80 and once over 443, following redirects only within your domain, and identifies itself as BitScore. It observes what a server volunteers and never acts on it. Nothing is submitted, no path other than the homepage is requested, and no port other than 80 and 443 is touched.
A clean result — does that mean we are secure?
It means three classes of finding are absent from what could be seen. Subdomain discovery is a floor rather than an inventory: a host with a private certificate and an unguessable name appears in no public log, and DKIM selectors cannot be enumerated at all. A finding here is evidence; an absence of findings is evidence only about what was found.

Which rules does this touch?

This tool is one skill out of nineteen.

What runs on this page is the browser-sized version of entity-scope, a skill in BitScoreCoWork — our MIT-licensed Claude plugin. The full version runs against your own Bitsight tenancy and works from your measured attack surface rather than a form. The source is public, so you can read exactly what it does before you run it.

Read the source →The Applied AI practice

Knowing the rule is the easy half.

This page tells you what you owe. It cannot tell you what an attacker already sees. Your organisation has a security rating calculated from signals visible from outside — request the complimentary Cyber Risk Rating Report and find out what it says. No agent, no system access, no questionnaire.

Request my rating →All free tools