Skip to content
RedSentinel

Website security checker for headers, SSL/TLS and DNS

Run a free, passive security check on a public website: security headers, HTTPS and certificate health, cookie flags and email authentication. The scan uses ordinary public requests only, with no exploit attempts.

What the security check looks at

The report focuses on configuration signals that can be observed from the outside, which is where many avoidable weaknesses live.

  • Security headers

    Content-Security-Policy, Strict-Transport-Security (HSTS), frame protection, Referrer-Policy, Permissions-Policy and X-Content-Type-Options, including weak or report-only policies.

  • HTTPS and SSL/TLS certificate

    HTTP to HTTPS redirect, certificate validity and expiry, hostname match, incomplete chains, self-signed certificates and the negotiated protocol.

  • Cookies and cross-origin settings

    Secure, HttpOnly and SameSite flags on session-like cookies, and permissive CORS headers. Cookie values are never stored.

  • DNS and email authentication

    SPF, DMARC and CAA records for the domain, evaluated when the domain actually receives mail.

  • Exposure signals

    security.txt, public source maps, subresource integrity and high-confidence secret patterns in the page. Matched values are never kept.

How to read the results

A finding describes what was observed. It is not a claim that your site was or can be broken into.

  • Severity and confidence

    Every finding carries a severity and a confidence level, so a medium-confidence hint is never presented like a confirmed critical issue.

  • Fix guidance

    Each issue explains the impact, shows an example configuration and tells you how to verify the fix.

  • Checks that could not run

    When a check times out or cannot complete, it is listed as not assessed and never changes your score.

Passive by design

The public scanner is meant to be safe to run on a site you are responsible for.

  • Ordinary public requests

    A small, bounded number of GET requests plus one TLS handshake and DNS lookups. No payloads, fuzzing, brute force or port scanning.

  • Public addresses only

    Private and internal addresses are refused, and every redirect is validated again before it is followed.

  • Minimal evidence

    Reports keep cookie names, never values, and secret patterns by label and count, never the matched text.

Scope and limits of the security check

A passive configuration check is useful and honest about what it cannot see.

  • Passive configuration check

    Headers, transport security, cookies, DNS mail records and exposure hints observed from public responses.

    Available today
  • Penetration testing and exploit scanning

    The anonymous scanner does not try to exploit anything. Authorised manual testing is a separate service performed by people.

    Not available
  • Full vulnerability assessment

    No port scans, directory enumeration, authenticated testing or application logic testing are performed.

    Not available
  • Legal compliance verdict

    Findings such as HTTPS or cookie flags can support a GDPR review, but the scan never certifies compliance with GDPR or any other regulation.

    Not available

Website security check questions

Is this a penetration test?

No. It is a passive check of publicly observable configuration. It does not attempt to exploit anything. If you need authorised hands-on testing, that is a separate service.

Is it safe to run on my production website?

The scan sends a small number of ordinary requests with bounded timeouts and no attack payloads, so it behaves much like a visitor and a monitoring tool would.

Can I scan any website?

Only publicly reachable sites. Private and internal addresses are refused. Scan sites you own or are authorised to assess.

Does the scan prove that I comply with GDPR?

No. It reports technical signals such as HTTPS and cookie flags that may help a privacy and security review. It is not a legal assessment or a certification.

My score is low. Where do I start?

Start with the critical and important findings at the top of the report, usually HTTPS, certificate and missing headers, then re-scan to confirm each fix.

See what your website exposes to the outside

Write to us or book a call and an expert will review your site with you.