Ironfang Security
External security scanning
Security checks
for your domains.
Ironfang checks DNS, TLS, HTTP security headers, email configuration and exposed services, then gives you prioritised findings with evidence and clear steps to fix them.
Free during the preview. No card required. Automated, low-impact checks on domains you verify.
Available now
External Security Check
Verify a domain, run a scan and review prioritised results a few minutes later. Every check runs from the public internet, against the configuration anyone can see.
Free during the preview
No card required. The same limits apply to every organisation.
Verified domains only
A DNS TXT record proves you control a domain before anything is scanned.
Low impact
DNS lookups, a few HTTP requests, TLS handshakes and single connections to common ports. Nothing is exploited.
Findings with fixes
Each finding has a severity, a confidence level, the evidence behind it and steps to fix it.
Getting started
How it works
Setup takes a few minutes. Most of that is waiting for DNS.
- 1Add a domainEnter the domain you want to check, such as example.co.uk. Pasting a full URL works too.
- 2Verify ownershipAdd the TXT record Ironfang gives you at your DNS provider. It is picked up automatically.
- 3Confirm authorisationReview what the scan does and confirm you are authorised to test the domain.
- 4Run the scanStart a scan from the portal. Most finish within a few minutes.
- 5Review findingsStart with the highest-priority findings. Each one explains the issue and how to fix it.
- 6RecheckAfter a fix, recheck the finding. Ironfang runs the relevant checks again and records the result.
Coverage
What we check
Ironfang reads your public configuration and makes a small number of ordinary requests. It never tries to get in.
Checked
- DNSAddress and nameserver records, CAA, DNSSEC, and CNAMEs that point at names that no longer exist.
- TLS and certificatesCertificate validity, expiry and hostname coverage, supported TLS versions and cipher strength.
- HTTP security headersHTTPS redirects, HSTS, Content Security Policy and other security headers, cookie attributes and security.txt.
- Email authenticationSPF, DMARC and DKIM, and protection for domains that should not send email. No email is sent.
- Exposed servicesOne connection attempt to each port on a fixed list of common services, such as databases and remote desktop.
- Exposed technologyThe web server, CDN and frameworks your responses disclose.
- Outdated softwareVersion strings that suggest unsupported software. Reported as potential issues, since vendors often patch without changing the version.
- Certificate transparencyHostnames from public certificate logs, listed for you to review. They are not scanned.
Never attempted
- Exploiting vulnerabilities
- Password and credential attacks
- Authentication attacks
- Fuzzing
- SQL injection
- Cross-site scripting
- Denial-of-service testing
- Destructive testing
- Social engineering
- Attempts to gain access
Each check is documented in the check reference. Scanner addresses and traffic are listed on the scanner page.
Verification
Scans run only on verified domains
Add a TXT record at your DNS provider and Ironfang verifies the domain as soon as the record appears.
Before the first scan you also confirm you are authorised to test the domain. The confirmation is recorded, and you are asked again if the scan policy changes.
The record is checked again before every scan. Remove it and scanning stops until it is back.
TXT record
- Type
- TXT
- Name
- _ironfang-verification.example.com
- Value
- ironfang-verification=k3v9q2mz7x4t8w1r
Authorisation
I confirm I am authorised to assess this domain.
Findings
Know what to fix first
Severity is the potential impact. Confidence is how strongly the evidence supports the finding. Use both to decide what to fix now and what to verify.
Severity
- Critical
- Serious exposure. Fix immediately.
- High
- Significant weakness. Fix soon.
- Medium
- Worth fixing.
- Low
- Minor hardening.
- Information
- Context, not a problem.
Confidence
- Confirmed
- Observed directly, such as a missing header.
- High
- Strong evidence.
- Medium
- Likely. Worth verifying.
- Potential
- Inferred, for example from a version string. Verify before acting.
Evidence and fixes
What Ironfang observed, such as the DNS answer, certificate or response headers, why it matters and how to fix it.
Triage
Acknowledge a finding, accept the risk or mark it a false positive, with a note for your team.
Rechecks
Recheck a single finding after a fix, without running a full scan. Findings are only marked fixed when a check confirms it.
Passed checks and history
Results show what is configured correctly too, and every scan stays in your history.
Pricing
Free during the preview
No card required. If paid plans are introduced, they will be announced before anything is charged.
Preview limits
- Up to 5 domains
- 20 scans per day
- One scan per domain every 60 minutes
- One active scan at a time
- One recheck per finding every 60 seconds
Roadmap
What's next
Planned additions, built on the same verified domains and findings.
- Planned
Continuous monitoring
Scheduled scans of your verified domains, with alerts when something changes.
- Planned
Attack surface
Discover the hostnames and services you expose, and bring them into scope when you choose.
- Planned
Compliance readiness
Use your findings and evidence to prepare for security questionnaires and certifications.
- Planned
Deeper assessments
More thorough testing under explicit authorisation, with people involved where judgement matters.
Questions
FAQ
- Is this a penetration test?
- No. Ironfang runs automated, low-impact checks against your public configuration and never tries to break in. It is not a penetration test, a certification or a formal security audit.
- Why do I need to verify my domain?
- So Ironfang only scans domains whose owners asked for it. The DNS record proves you control the domain, and your confirmation records that you are authorised to test it.
- Will a scan affect my site?
- It should not. A scan makes a handful of HTTP requests and TLS handshakes and one connection attempt per listed port, rate-limited per host. No logins, no form submissions and no load testing.
- What does it cost?
- Nothing during the preview, and no card is required. You can add up to 5 domains and run up to 20 scans a day.
- Can I scan a domain I do not own?
- Only if you are authorised to test it and can add a DNS record to it, such as a client domain you manage with their permission.
- Are subdomains scanned?
- Not automatically. Hostnames found in certificate transparency logs are listed for you to review. A scan covers the domain you verified and its www host.
- Our firewall blocked the scan. What now?
- Allow the scanner's source address and User-Agent, listed on the scanner page, then run the scan again. Ironfang never switches addresses to get around a block.
- What happens to the results?
- They stay in your organisation's account: scan history, findings, evidence and status changes. Removing a domain stops scanning and keeps its history.
Get started
Check your first domain
Add a domain, verify it with one DNS record and get results in a few minutes.
Free during the preview. Automated external checks, not a penetration test or certification.

