Tools · No sign-up
Tools
Scanners for websites, email, and links; a dedicated email header analyzer and GUID / UUID converter; AI-era helpers (tokens, JWTs, TLS, disclosure files); and a password generator with strength meter and breach check on the Security tools page. Runs in your browser or via our APIs; we do not store your inputs in an application database.
Use Scan hub for headers, domain email DNS, and phishing checks on one page. Use Password generator & security tools for passphrase generation, strength meter, HIBP-style breach check, and hashes.
Scan hub (all-in-one)
Run security headers, domain MX/SPF/DKIM/DMARC lookups, and phishing URL checks from a single dashboard.
Open scan hubWebsite, email & link scanners
Individual pages for each scanner: same behavior as the scan hub, one tool per screen.
Security Headers Scanner
Check CSP, HSTS, X-Frame-Options and get a grade.
Check your site's HTTP security headers (CSP, HSTS, X-Frame-Options) and get an instant grade.
Use tool →Domain Email DNS Checker
MX, SPF, DKIM, DMARC and TXT records for any domain.
Domain DNS lookup for email: MX, SPF (TXT), DMARC at _dmarc, DKIM at selector._domainkey, nameservers. Table output.
Use tool →Phishing URL Checker
Quick heuristic check for suspicious link indicators.
Check a URL for common phishing-style indicators. Heuristic only; use with caution.
Use tool →
Raw email message analysis
Inspect a single email's headers (not DNS at the domain level).
AI & API security
LLM token budgeting, prompt hygiene heuristics, and JWT inspection for APIs and identity (no model calls from this site).
AI prompt helper
Rough token estimate, length stats, prompt-injection heuristics.
Budget LLM API calls and scan pasted prompts for common jailbreak-style wording. Browser-only; no model requests.
Use tool →JWT decoder
Decode header & payload; exp/iat; signature bytes (not verified).
Inspect JSON Web Tokens for APIs, IdPs, and many AI gateways. Everything stays in your browser.
Use tool →
TLS & disclosure
Certificate and protocol spot checks plus security.txt for coordinated vulnerability reporting.
TLS / HTTPS inspector
Protocol, cipher, ALPN, certificate chain on port 443.
One check against public hosts: TLS version, cipher suite, and PEM-style chain summary.
Use tool →security.txt fetcher
RFC 9116 disclosure file from /.well-known/ or /.
Fetch security.txt over HTTPS for vulnerability disclosure contacts and canonical URLs.
Use tool →
Developer & format tools
Encode and convert identifiers locally in your browser.