Skip to content

External Security Check

Check your domain's external security

Verify a domain with one DNS record, then scan its DNS, TLS, HTTP headers, cookies, email records and exposed services. Every finding includes the evidence, why it matters and how to fix it.

Run security checkRead the docs

  • Free during the preview
  • Verified by DNS
  • No exploitation or logins
  • Per-finding rechecks

Finding

HSTS is not enabled

Open

MediumConfirmedRecommended hardeningexample.com

What we found

HTTPS responses do not include a Strict-Transport-Security header.

How to fix it

Add this header to HTTPS responses once every subdomain serves HTTPS:

Strict-Transport-Security: max-age=31536000; includeSubDomains

Recheck once fixed

Why it matters

Configuration drifts

DNS records outlive the services they pointed at. Certificates approach expiry. Headers disappear in a migration, and a database port stays open after a test. Little of this shows from inside your network, and most of it is visible from outside.

The External Security Check looks from outside, with your permission, and turns what it sees into findings with evidence and a fix.

; The record that proves you control the domain
type   TXT
name   _ironfang-verification.example.com
value  ironfang-verification=k3v9q2mz7x4t8w1r

; One finding from the check
{
  "key": "http.hsts_missing",
  "title": "HSTS is not enabled",
  "severity": "medium",
  "confidence": "confirmed",
  "kind": "hardening",
  "host": "example.com",
  "status": "open",
  "docs_url": "https://ironfang.com/security/checks/hsts"
}

Capabilities

What we check

Six areas in one scan. Every finding has a severity and a separate confidence.

  • DNS

    Address records, nameserver redundancy, CAA, DNSSEC and dangling CNAMEs.

  • TLS and HTTPS

    HTTPS availability, certificate trust, expiry and hostname coverage, TLS versions and cipher suites.

  • HTTP security headers

    HTTPS redirects, HSTS, Content Security Policy, X-Content-Type-Options, clickjacking protection, Referrer-Policy, Permissions-Policy, version banners, cookie attributes and security.txt.

  • Email authentication

    SPF, DMARC and DKIM at common selectors, and protection for domains that send no email. Read from DNS only.

  • Exposed services

    One connection attempt per port on a fixed list of common services, including databases, remote desktop, SMB and the Docker API.

  • Technology and discovery

    Software your responses disclose, versions that look unsupported (reported as potential) and hostnames from certificate logs, listed but never scanned.

Use cases

When to run it

Before changes ship, after they land, and whenever someone asks.

Before a launch

Check certificates, headers and redirects before customers arrive.

After a migration

Moving hosting, CDN or DNS is when records get left behind and headers go missing.

Security questionnaires

When a customer asks about your security, start from what is actually configured.

Email spoofing

Check that SPF and DMARC stop others sending mail as your domain.

After a fix

Recheck the finding and keep a record of when it was fixed.

Client domains

Check domains you manage for clients, with their permission and access to their DNS.

Never attempted

No exploitation, password or authentication attacks, SQL injection, cross-site scripting, fuzzing, denial-of-service or destructive testing, social engineering or attempts to gain access. This is an automated external check, not a penetration test, a certification or a formal audit.

Pricing

Free during the preview

No card required. The limits on domains, scans and rechecks are listed in the docs.

Ironfang Security

Questions

FAQ

Verification, scan traffic and how to read results.

How is ownership verified?
Add the TXT record from the portal at your DNS provider. Once Ironfang sees it, the domain is verified. The record is checked again before every scan.
What do I confirm before the first scan?
That you are authorised to test the domain. The confirmation is recorded against the current scan policy, and you are asked again when the policy changes.
How much traffic does a scan send?
Very little: DNS lookups through public resolvers, a handful of HTTP requests and TLS handshakes per host, and one connection attempt per listed port, rate-limited per address.
Why is a finding marked "Potential"?
It was inferred, usually from a version string, rather than observed. Vendors often patch software without changing the version it advertises, so confirm it on the server before acting.
How does the DKIM check work?
It looks for keys at the selectors common mail services use. Selectors cannot be listed from outside, so if none is found the result says DKIM could not be confirmed, not that it is missing.
What happens when I recheck a finding?
The checks behind it run again on its host. If the issue is gone, the finding is marked fixed; if not, it stays open. Both results are kept in its history.
Is this a penetration test?
No. A penetration test is a person attempting to break in under an agreed scope. This is an automated check of public configuration that attempts nothing intrusive.

Less to operate. More to ship.

Run your first scan

Create an account, add a domain and its verification record, and get results in a few minutes.

Free during the preview. No card required.