Domain Security Monitor
Verify ownership and monitor TLS, DNS, email security, headers and domain expiry.
FREE · PRACTICAL · PRIVACY-AWARE
Use the complete English collection of password, network, web security and developer utilities from one place.
36 FOCUSED UTILITIES
Local tools process values only in your browser. Network tools query public technical records and never ask for credentials.
Verify ownership and monitor TLS, DNS, email security, headers and domain expiry.
Bring local learning progress, checklists, reading and recent results into one view.
Review DNS, TLS, HTTP headers and email protections in one report.
Generate cryptographically secure passwords locally in your browser.
Evaluate length, variety and predictable patterns without sending the password.
Create SHA-256, SHA-384 or SHA-512 digests from text or local files.
See the public IP and technical details shared by your browser.
Review common public DNS records for a domain.
Inspect MX, SPF, DMARC, DKIM, MTA-STS and TLS-RPT records.
Check the browser security headers returned by a public HTTPS site.
Inspect certificate validity, issuer, host coverage and TLS details.
Calculate network, broadcast, mask and usable host ranges.
Encode and decode Base64 or URL values locally in your browser.
Build a practical Content-Security-Policy header from safe presets.
Review registrar, lifecycle dates, status codes, nameservers and DNSSEC.
Analyze authentication, identity alignment and delivery hops locally.
Compare files and create SHA or Subresource Integrity values locally.
Check secure context, WebAuthn and device authenticator support.
Inspect suspicious URLs locally without opening or submitting the destination.
Find common API key, token and private-key patterns in local text or configuration files.
Decode JWT structure locally and review expiry, algorithm and sensitive-claim signals.
Build a practical five-stage response checklist for common cyber incidents.
Read CycloneDX and SPDX JSON inventories locally and review version or license gaps.
Review Secure, HttpOnly, SameSite, scope and prefix rules in Set-Cookie headers.
Review Apache, Nginx and SSH logs locally for errors, failed sign-ins, suspicious paths and high-volume sources.
Extract, deduplicate and safely defang network indicators and common file hashes from incident notes.
Calculate a standards-compatible technical severity score and vector from the eight base metrics.
Decode supported QR images locally and inspect the payload without opening its destination.
Build reviewable SPF and staged DMARC starter records from explicitly authorized mail sources.
Score 24 controls across six security areas and turn gaps into a prioritized local roadmap.
Combine NVD severity, CISA KEV evidence and FIRST EPSS probability for one explainable CVE priority.
Build an RFC 9116 starter file and validate the live .well-known publication on a public domain.
Inspect mixed scripts, Punycode, invisible characters and common cross-script lookalikes locally.
Review API contracts locally for unprotected operations, missing schemes and sensitive endpoint signals.
Turn system scope, assets and trust boundaries into prioritized threats, mitigations and validation tasks.
Practice critical decisions in four guided scenarios and measure response quality locally.
Try another keyword or category.
Only test systems you own or are explicitly authorized to assess. Results are informational and do not replace a professional security review.
Read our security approach →