Free domain security scan

See where your domainis exposed in 30 seconds.

Enter your domain and we'll run a read-only check for the most common email and website security gaps. You'll get a plain-English report with what to fix and how.

Read-only No signup Public records only
Try:

We only check publicly published DNS records and HTTPS response headers. No login, no port scan, no probing of private services.

What this scan checks

Four categories that cover the most common, most preventable weaknesses on an Australian business domain.

Email authentication

SPF, DMARC, DKIM and MX. The same checks attackers use to spoof your business.

DNS hardening

DNSSEC validation so DNS answers can't be tampered with in transit.

Website security

HTTPS, HSTS, CSP, clickjacking protection and version disclosure.

Plain English advice

Every check explains what it means and exactly what to fix.

Australian Cyber Risk in Context

What the Australian data is telling us.

Figures published by the Office of the Australian Information Commissioner (OAIC) and the Australian Cyber Security Centre (ACSC). The point is not to alarm you. It is to make sure decisions are based on real local data.

Most incidents we see are not sophisticated. They are predictable, preventable, and well covered by frameworks like the ACSC Essential Eight and SMB1001.

That is why our four capabilities sit under one agreement. Cybersecurity is built in, not bolted on. Essential Eight and SMB1001 evidence is documented as we go.

60%

of SMBs close within 6 months after a cyber breach

OAIC Data Breach Statistics 2024

$3.35M

average total cost of a data breach in Australia

OAIC Data Breach Statistics 2024

23 days

average downtime from a ransomware attack

OAIC Ransomware Analysis 2024

1,700+

notifications of malicious cyber activity in FY2024-25

ACSC Annual Threat Report 2024-25

67%

of breaches caused by malicious attacks

OAIC Breach Analysis 2024

1,549

data breaches reported to OAIC in 2024

OAIC Notifiable Data Breaches Register

8.2M

individuals affected by data breaches in Australia 2024

OAIC Data Breach Statistics 2024

287 days

average time to identify and contain a breach

OAIC Data Breach Statistics 2024

In plain English

Email authentication

SPF, DMARC and DKIM are how mail providers tell legitimate email from spoofed email. Missing or weak records are one of the most common causes of business email compromise.

DNSSEC

DNSSEC adds a tamper-proof signature to DNS answers so attackers can't redirect your domain in transit. Many Australian businesses still don't have it on.

HTTPS and redirects

We confirm HTTPS works and that plain HTTP redirects properly. Mixed or missing HTTPS is a flag for browsers and search engines.

Security headers

HSTS, CSP, X-Frame-Options and friends. These are quick wins that block whole categories of common web attacks.

Aligned to controls referenced by the ACSC Information Security Manual, ACSC Essential Eight guidance, and the SMB1001 standard for Australian small and medium business.