Free security scan

Get the security score of your domain

Enter your company domain or subdomain. The scan covers TLS encryption, HTTP security headers and email security, and ends with a 0 to 100 risk score calculated with the platform formula.

Accepts a domain or subdomain, such as app.yourcompany.com. Each address is scanned separately.

No sign-up to see the resultResult in ~40 secondsPassive external scan
or scan a single area
What is analyzed

Encryption, headers and email assessed in a single score

The scan analyzes the address you enter with the cidguard platform scanners and combines the results into a risk score from 0 to 100, graded from A to D. It uses the same formula subscribers see, with the same weights per risk pillar.

The scan runs against your server, in real time. The TLS handshake happens against your host, headers are read from your page response and email records come from your DNS. In about forty seconds the score shows up on screen, and each finding includes severity, evidence and step-by-step remediation.

With the result, your technical team knows what to fix first, your hosting provider gets clear instructions and your company has a document to share with customers and partners.

Checks

What the scan checks

Three areas analyzed on the address you enter, each with the technical references behind every finding.
01

Encryption in transit

Accepted protocol versions, cipher strength, forward secrecy, downgrade protection and the Heartbleed and ROBOT flaws.
RFC 8996RFC 7507CVE-2014-0160
02

Security headers

Effective CSP policy, HSTS coverage, clickjacking protection, CORS and HTTP to HTTPS redirection.
RFC 6797W3C CSP 3OWASP
03

Domain identity

Whether the domain is protected against spoofed email: SPF, DKIM, DMARC policy, alignment, MTA-STS and TLS in transport.
RFC 7208RFC 7489RFC 8461
Why it matters

What customers, partners and auditors look at

Encryption, headers and email show up in vendor security questionnaires, in mailbox provider requirements and in audit standards.
2020

Browsers stopped accepting TLS 1.0 and 1.1

Chrome, Firefox, Safari and Edge removed support for both versions in 2020. Security questionnaires from customers and partners ask which versions your server still offers.

2024

Gmail and Yahoo started requiring DMARC

Since February 2024, bulk email senders must publish DMARC. With a quarantine or reject policy, spoofed messages in your company name stop reaching your customers.

PCI DSS 4.0

Encryption and scripts are now audited

Requirement 4.2.1 calls for strong cryptography in data transmission, and 6.4.3 calls for control of the scripts on payment pages. ISO 27001 and privacy laws such as GDPR expect equivalent technical controls.

How it works

From address to report

Enter a domain or subdomain. The score shows up on screen and the full report is sent by email.
10 s

Enter the address

Domain or subdomain. No account, no credit card and nothing to install.

20 s to 40 s

The scan runs

The platform scanners analyze the address in real time.

3~40 s

The score shows up

A score from 0 to 100 with findings grouped by severity.

4Right after

The report arrives by email

Full PDF, sent to an email address at the scanned domain.

Sample result
acme.comscore67C
TLS3 findingsTLS 1.0 accepted 路 4 ciphers without PFS 路 TLS_FALLBACK_SCSV missing
HTTP2 findingsContent-Security-Policy missing 路 HSTS without preload
Email1 findingDMARC set to p=none
PDF report sent to an email address at acme.com
What the report includes
  • 01Risk score from 0 to 100 and grade from A to D
  • 02Findings grouped by severity
  • 03Technical evidence for each finding
  • 04Step-by-step remediation
  • 05References: RFCs, CWE and best practices
cidguard platform

The same analysis across all your assets, continuously

For subscribers, the analysis goes deeper, covers every company asset and tracks how the score changes each cycle.
01

Every company asset

Domains, subdomains and exposed services are discovered and added to monitoring automatically.

02

Deeper analysis

Applications, infrastructure, DNS and email assessed in depth, with dedicated checks for each area.

03

Rescan every 35 days

Each asset is reassessed every cycle, and fixed issues are closed once a new scan confirms them.

04

Audit-ready reports

PDF reports with findings mapped to ISO 27001 controls, ready for customers and auditors.

FAQ

Frequently asked questions

Is the scan really free?

Yes. The score, the severity count and the findings show up on screen with no sign-up. Your email is only requested to send the full PDF report, with evidence and remediation for each finding.

Do I need to authorize anything?

No. The scan makes the same contact with your domain that a browser or a mail server makes: it opens a secure connection, reads the home page response and queries public DNS records. Nothing in your environment is changed.

How is the score calculated?

The score goes from 0 to 100, and the lower it is, the lower the risk. Each finding is weighted by severity and risk pillar, using the same formula as the platform. The grade follows the score: A below 40, B from 40 to 64, C from 65 to 84 and D from 85.

Can I scan a subdomain?

Yes. Enter the full address, such as app.yourcompany.com, and it is scanned on its own. On the platform, company subdomains are discovered and monitored automatically.

Why is the report sent to an email at the scanned domain?

The report contains technical details about the domain, so it is sent to an address at that domain. Consultants and agencies working for the company can request the report through the contact page.

Is my data stored?

Scan results stay available for seven days and then expire. The email you provide is used to send the report and related communications, with one-click unsubscribe. Nothing is published or shared, and result pages do not appear in search engines.

What does the platform add?

The platform finds every company asset, analyzes each one in depth and repeats the analysis every 35 days. Fixed issues are closed automatically after a new scan, and the score shows how your company evolves over time.

Can I run the scan again after fixing issues?

Yes. Results for an address are cached for 24 hours; after that, a new scan runs normally and shows the updated score.