Free tools
Small security checks, free forever
One-off versions of checks Attack Surface Scan runs continuously. No signup, no email gate, and nothing you type reaches our servers: the DNS tools query public DNS-over-HTTPS resolvers straight from your browser, and the builders and policy generators never touch the network.
Attack surface scanner
Map a domain's subdomains and certificates from certificate transparency logs, see which hosts still resolve, and spot third-party hosting and unexpected CAs. Passive only.
Open the tool →
Subdomain takeover checker
Find dangling CNAME records pointing at targets that no longer exist: the DNS leftovers that become subdomain takeovers. Sweeps common subdomains too.
Open the tool →
SPF & DMARC checker
Can strangers send mail as your domain? Reads your records, counts SPF DNS lookups against the limit of 10, and grades the policy receivers enforce.
Open the tool →
CSP builder
Describe your site and get a copy-paste Content-Security-Policy header, with plain-spoken warnings whenever a choice quietly defeats the policy.
Open the tool →
Lookalike domain checker
Find typosquats of your domain that are already registered: generates up to 200 lookalikes, checks each over public DNS, and flags the ones that can receive mail.
Open the tool →
Security policy generators
Build security policies that match how your team actually works. Answer a few questions to map controls to frameworks like SOC 2 or ISO 27001, then download in Word, Markdown or PDF. Everything runs in your browser, so there's no email required.
Access control policy generator
Generic access policies fail audits because they promise checks you cannot prove. Generate a clean policy tailored to your identity setup, complete with review cadences and compliance mappings, with no email gate.
Open the tool →
Password policy generator
Stop copying outdated templates that force 90-day password rotations. Build a modern password and authentication policy based on NIST guidelines, complete with MFA rules and compliance mappings, in five minutes.
Open the tool →
Incident response policy generator
Generic incident response templates fall apart during audits. Build a custom policy with realistic severity levels, defined response roles, and legal notification timelines in minutes, without handing over your email.
Open the tool →
Vulnerability management policy generator
Stop copying generic templates that promise fix windows you cannot hit. Build a realistic vulnerability management policy mapped to SOC 2 and ISO 27001, then export it instantly without giving up your email.
Open the tool →
Data retention policy generator
Auditors will ask how long you keep customer data, production logs, and backups. Build a clean, defensible retention schedule mapped to your actual compliance frameworks in two minutes.
Open the tool →
Why free? Because each of these is one snapshot of a thing that drifts. If the snapshot is useful, the monitoring is the product.
Checked once. Now have it watched.
Every check on this page is a point-in-time answer to a question that changes: records drift, vendors restructure their DNS, deploys drop headers. Attack Surface Scan asks the same questions of your verified domains every night and tells you when the answer changes.
7-day trial of the full product, no card required. Scanning needs domain ownership verified (DNS record, site file, work email or emailed approval): Attack Surface Scan never scans anything you haven't proved you control.