Free

See your external security posture —
in under 5 minutes.

Spotter is a free external security scan that grades your organization A through F across six categories — using 14 specialized tools and only publicly available data. No agents, no credentials, no access to your network. Just your domain name.

Already have an account? Sign in and run a scan in under 60 seconds.

Fourteen tools. Six categories. One letter grade.

Every scan combines results from 14 specialized tools into a weighted score across six security categories and an overall A–F grade. Any CRITICAL finding caps the overall grade at D — because one wide-open door is enough.

01

Port Scanning & Service Detection

Live nmap scanning identifies open ports, running services, OS fingerprinting, and known CVEs across your public infrastructure.

02

TLS/SSL Deep Analysis

testssl.sh cipher suite analysis, protocol version checks, and vulnerability detection for Heartbleed, POODLE, BEAST, and more.

03

HTTP Security Headers

Checks for Content-Security-Policy, HSTS, X-Frame-Options, and other critical headers most websites are missing.

04

Exposed File Detection

Probes for accidentally exposed .git directories, .env files, database backups, admin panels, and other sensitive paths.

05

Technology Fingerprinting

Identifies your CMS, web server version, JavaScript frameworks, and other technologies — flagging outdated or vulnerable versions.

06

WAF Detection

Detects whether a Web Application Firewall is protecting your web applications and identifies the specific product.

07

Subdomain Enumeration

Discovers subdomains via Certificate Transparency logs and passive OSINT — finding forgotten dev, staging, and admin portals.

08

Email & Employee OSINT

Harvests publicly exposed email addresses and employee names from search engines, certificates, and DNS records.

09

Breach Exposure

Checks your domain against breach databases to identify compromised credentials associated with your organization.

10

Email Authentication

Validates SPF, DMARC, DKIM, MTA-STS, and BIMI configuration to assess email spoofing and phishing resistance.

11

DNS & Domain Intelligence

WHOIS registration, DNS record analysis, DNSSEC validation, and zone transfer testing.

12

Domain Reputation

Checks your domain against DNS blocklists, URLhaus malware databases, and abuse databases.

13

Cookie Security Analysis

Evaluates cookie flags — Secure, HttpOnly, SameSite — and analyzes robots.txt for intelligence on hidden paths.

14

SSL Certificate Health

Certificate chain validation, expiration monitoring, issuer verification, and HSTS preload status.

Three steps. No sales call required.

01

Request Access

Fill out a short form. We review each request personally — no bots, no crawlers, no automated sign-ups.

02

Run a Scan

Sign in, enter your domain, and start the scan. Quick Scan finishes in under 2 minutes, Full Scan in under 5.

03

Download Your Report

A branded PDF with an overall letter grade, six category scores, detailed findings, and a prioritized remediation plan.

Common questions about Spotter.

Ready to run your scan?

Access is free. Reports are yours to keep. No strings attached.