Skip to content

Ironfang Security

External security scanning

Security checks
for your domains.

Ironfang checks DNS, TLS, HTTP security headers, email configuration and exposed services, then gives you prioritised findings with evidence and clear steps to fix them.

Free during the preview. No card required. Automated, low-impact checks on domains you verify.

Available now

External Security Check

Verify a domain, run a scan and review prioritised results a few minutes later. Every check runs from the public internet, against the configuration anyone can see.

About the External Security Check
  • Free during the preview

    No card required. The same limits apply to every organisation.

  • Verified domains only

    A DNS TXT record proves you control a domain before anything is scanned.

  • Low impact

    DNS lookups, a few HTTP requests, TLS handshakes and single connections to common ports. Nothing is exploited.

  • Findings with fixes

    Each finding has a severity, a confidence level, the evidence behind it and steps to fix it.

Getting started

How it works

Setup takes a few minutes. Most of that is waiting for DNS.

  1. 1Add a domainEnter the domain you want to check, such as example.co.uk. Pasting a full URL works too.
  2. 2Verify ownershipAdd the TXT record Ironfang gives you at your DNS provider. It is picked up automatically.
  3. 3Confirm authorisationReview what the scan does and confirm you are authorised to test the domain.
  4. 4Run the scanStart a scan from the portal. Most finish within a few minutes.
  5. 5Review findingsStart with the highest-priority findings. Each one explains the issue and how to fix it.
  6. 6RecheckAfter a fix, recheck the finding. Ironfang runs the relevant checks again and records the result.

Coverage

What we check

Ironfang reads your public configuration and makes a small number of ordinary requests. It never tries to get in.

Checked

  • DNSAddress and nameserver records, CAA, DNSSEC, and CNAMEs that point at names that no longer exist.
  • TLS and certificatesCertificate validity, expiry and hostname coverage, supported TLS versions and cipher strength.
  • HTTP security headersHTTPS redirects, HSTS, Content Security Policy and other security headers, cookie attributes and security.txt.
  • Email authenticationSPF, DMARC and DKIM, and protection for domains that should not send email. No email is sent.
  • Exposed servicesOne connection attempt to each port on a fixed list of common services, such as databases and remote desktop.
  • Exposed technologyThe web server, CDN and frameworks your responses disclose.
  • Outdated softwareVersion strings that suggest unsupported software. Reported as potential issues, since vendors often patch without changing the version.
  • Certificate transparencyHostnames from public certificate logs, listed for you to review. They are not scanned.

Never attempted

  • Exploiting vulnerabilities
  • Password and credential attacks
  • Authentication attacks
  • Fuzzing
  • SQL injection
  • Cross-site scripting
  • Denial-of-service testing
  • Destructive testing
  • Social engineering
  • Attempts to gain access

Each check is documented in the check reference. Scanner addresses and traffic are listed on the scanner page.

Verification

Scans run only on verified domains

Add a TXT record at your DNS provider and Ironfang verifies the domain as soon as the record appears.

Before the first scan you also confirm you are authorised to test the domain. The confirmation is recorded, and you are asked again if the scan policy changes.

The record is checked again before every scan. Remove it and scanning stops until it is back.

TXT record

Type
TXT
Name
_ironfang-verification.example.com
Value
ironfang-verification=k3v9q2mz7x4t8w1r

Authorisation

I confirm I am authorised to assess this domain.

Findings

Know what to fix first

Severity is the potential impact. Confidence is how strongly the evidence supports the finding. Use both to decide what to fix now and what to verify.

Severity

Critical
Serious exposure. Fix immediately.
High
Significant weakness. Fix soon.
Medium
Worth fixing.
Low
Minor hardening.
Information
Context, not a problem.

Confidence

Confirmed
Observed directly, such as a missing header.
High
Strong evidence.
Medium
Likely. Worth verifying.
Potential
Inferred, for example from a version string. Verify before acting.
  • Evidence and fixes

    What Ironfang observed, such as the DNS answer, certificate or response headers, why it matters and how to fix it.

  • Triage

    Acknowledge a finding, accept the risk or mark it a false positive, with a note for your team.

  • Rechecks

    Recheck a single finding after a fix, without running a full scan. Findings are only marked fixed when a check confirms it.

  • Passed checks and history

    Results show what is configured correctly too, and every scan stays in your history.

Pricing

Free during the preview

No card required. If paid plans are introduced, they will be announced before anything is charged.

Preview limits

  • Up to 5 domains
  • 20 scans per day
  • One scan per domain every 60 minutes
  • One active scan at a time
  • One recheck per finding every 60 seconds

Roadmap

What's next

Planned additions, built on the same verified domains and findings.

  • Planned

    Continuous monitoring

    Scheduled scans of your verified domains, with alerts when something changes.

  • Planned

    Attack surface

    Discover the hostnames and services you expose, and bring them into scope when you choose.

  • Planned

    Compliance readiness

    Use your findings and evidence to prepare for security questionnaires and certifications.

  • Planned

    Deeper assessments

    More thorough testing under explicit authorisation, with people involved where judgement matters.

Questions

FAQ

Is this a penetration test?
No. Ironfang runs automated, low-impact checks against your public configuration and never tries to break in. It is not a penetration test, a certification or a formal security audit.
Why do I need to verify my domain?
So Ironfang only scans domains whose owners asked for it. The DNS record proves you control the domain, and your confirmation records that you are authorised to test it.
Will a scan affect my site?
It should not. A scan makes a handful of HTTP requests and TLS handshakes and one connection attempt per listed port, rate-limited per host. No logins, no form submissions and no load testing.
What does it cost?
Nothing during the preview, and no card is required. You can add up to 5 domains and run up to 20 scans a day.
Can I scan a domain I do not own?
Only if you are authorised to test it and can add a DNS record to it, such as a client domain you manage with their permission.
Are subdomains scanned?
Not automatically. Hostnames found in certificate transparency logs are listed for you to review. A scan covers the domain you verified and its www host.
Our firewall blocked the scan. What now?
Allow the scanner's source address and User-Agent, listed on the scanner page, then run the scan again. Ironfang never switches addresses to get around a block.
What happens to the results?
They stay in your organisation's account: scan history, findings, evidence and status changes. Removing a domain stops scanning and keeps its history.

Get started

Check your first domain

Add a domain, verify it with one DNS record and get results in a few minutes.

Free during the preview. Automated external checks, not a penetration test or certification.