Tools  /  Cyber Check

See your business the way an attacker does.

A free external posture check. Point it at any domain you operate. Under a minute, nothing installed, nothing behind a login.

Step one

Enter a domain.

Any domain you own or want to check. The tool normalises the input, so example.com.au and a full URL resolve to the same assessment.

This tool performs passive external reconnaissance against data that is already public: DNS records, certificate transparency logs, Mozilla Observatory. It does not attempt to exploit, guess credentials, or scan ports. It is safe to run against a domain you do not yet own, and it will never touch anything behind a login.

How this works

What gets checked, honestly.

Exactly what the tool does, and what it does not, so you can judge the report for yourself.

01

DNS and email

SPF, DMARC, DKIM, DNSSEC, CAA. Whether someone can spoof your email or hijack your domain.
02

Certificates and TLS

Every certificate ever issued for your domain, from the public CT logs. Subdomain sprawl and forgotten boxes surface here.
03

Web headers

CSP, HSTS, cookies and the rest, graded by Mozilla Observatory. You get the grade and the exact fix.
04

Brand and typosquats

Lookalikes of your domain, resolved and flagged. That is where phishing kits live before they come for your staff.
05

What it does not do

No port scanning, no credentials, no exploits. Passive external recon only, and honest about it.
06

Want a real red team?

For internal reviews, phishing simulations, Microsoft 365 hardening or Essential Eight uplift, talk to us. Small business prices. Book a conversation
Why this matters

Small business is not exempt any more.

The legal floor moved in both Australia and New Zealand. These findings map straight onto the posture regulators, insurers and auditors look at first.

Talk it through