Before a launch
Check certificates, headers and redirects before customers arrive.
External Security Check
Verify a domain with one DNS record, then scan its DNS, TLS, HTTP headers, cookies, email records and exposed services. Every finding includes the evidence, why it matters and how to fix it.
Run security checkRead the docs
Finding
HSTS is not enabled
MediumConfirmedRecommended hardeningexample.com
What we found
HTTPS responses do not include a Strict-Transport-Security header.
How to fix it
Add this header to HTTPS responses once every subdomain serves HTTPS:
Strict-Transport-Security: max-age=31536000; includeSubDomainsRecheck once fixed
Why it matters
DNS records outlive the services they pointed at. Certificates approach expiry. Headers disappear in a migration, and a database port stays open after a test. Little of this shows from inside your network, and most of it is visible from outside.
The External Security Check looks from outside, with your permission, and turns what it sees into findings with evidence and a fix.
; The record that proves you control the domain
type TXT
name _ironfang-verification.example.com
value ironfang-verification=k3v9q2mz7x4t8w1r
; One finding from the check
{
"key": "http.hsts_missing",
"title": "HSTS is not enabled",
"severity": "medium",
"confidence": "confirmed",
"kind": "hardening",
"host": "example.com",
"status": "open",
"docs_url": "https://ironfang.com/security/checks/hsts"
}Capabilities
Six areas in one scan. Every finding has a severity and a separate confidence.
Address records, nameserver redundancy, CAA, DNSSEC and dangling CNAMEs.
HTTPS availability, certificate trust, expiry and hostname coverage, TLS versions and cipher suites.
HTTPS redirects, HSTS, Content Security Policy, X-Content-Type-Options, clickjacking protection, Referrer-Policy, Permissions-Policy, version banners, cookie attributes and security.txt.
SPF, DMARC and DKIM at common selectors, and protection for domains that send no email. Read from DNS only.
One connection attempt per port on a fixed list of common services, including databases, remote desktop, SMB and the Docker API.
Software your responses disclose, versions that look unsupported (reported as potential) and hostnames from certificate logs, listed but never scanned.
Use cases
Before changes ship, after they land, and whenever someone asks.
Check certificates, headers and redirects before customers arrive.
Moving hosting, CDN or DNS is when records get left behind and headers go missing.
When a customer asks about your security, start from what is actually configured.
Check that SPF and DMARC stop others sending mail as your domain.
Recheck the finding and keep a record of when it was fixed.
Check domains you manage for clients, with their permission and access to their DNS.
No exploitation, password or authentication attacks, SQL injection, cross-site scripting, fuzzing, denial-of-service or destructive testing, social engineering or attempts to gain access. This is an automated external check, not a penetration test, a certification or a formal audit.
Pricing
No card required. The limits on domains, scans and rechecks are listed in the docs.
Questions
Verification, scan traffic and how to read results.
Less to operate. More to ship.
Create an account, add a domain and its verification record, and get results in a few minutes.
Free during the preview. No card required.