Resources · Tools

SECURITY TOOLS

Six quick checks you can run right away: email domain, website headers, password and address in breach lists, password generator and file hash. No account needed.

What is available

Six tools, six different places

Each tool looks at one specific place and answers one question. The result appears straight on the page, including an explanation of what the individual findings mean and why they matter. There is no account to create and nothing is unlocked in exchange for your contact details. The one exception is the breach check for an address — there we do need the address, because that is where the verification link goes. Querying a breach database about someone else's mailbox without the owner confirming it would not be right.

DNS · SPF, DKIM, DMARC

Email domain security

Reads the SPF and DMARC records and the DKIM selector you choose from public DNS. Shows how strictly the rules are written and whether SPF stays within the limit of ten DNS lookups. Useful when you are dealing with fraudulent messages sent in your name, or with the deliverability of your own mail.

Open the check →
HTTP · response headers

Website security headers

Fetches the response headers the way an ordinary browser does and goes through HSTS, the content policy, Referrer-Policy, Permissions-Policy and protection against framing the page. Useful before a site goes live, or when you need to know what the site has configured and what it does not.

Open the check →
Breaches · check in the browser

Is your password in a breach?

Compares the password against a list of passwords from publicly known breaches. The hash is computed in the browser and only its first five characters are sent out; the password itself never leaves the browser. Useful when you are picking a new password, or checking one you have been using somewhere for years.

Open the check →
Passwords · generated in the browser

Password and passphrase generator

Generates a random password of the length you choose, or a passphrase from English words, and shows the entropy of each in bits. The randomness comes from the operating system generator and the whole computation runs in the browser — the generated password is never sent anywhere and never stored.

Open the generator →
Breaches · mailbox verification

Is your address in a data breach?

Compares the email address against lists from publicly known breaches. The result is shown only after you confirm the link sent to that mailbox — so nobody can look up someone else's address without the owner knowing.

Open the check →
Files · hash in the browser

Is this file known malware?

Computes the hash of the file directly in your browser and compares it against a database of confirmed malware. The file never leaves your device — only the 64 characters of the hash are sent. Useful for a suspicious attachment you would rather not open.

Open the check →
The results are indicative The tools work only with what is visible from the outside, and with the state at the moment of the query: the email domain check reads DNS records, the website check reads response headers, the password check and the generator run entirely in your browser, and the address and file checks query public breach and malware databases. They do not test for vulnerabilities, do not get past a login and send nothing an ordinary browser or mail server would not send. A good result therefore means that at that one point a sensible configuration is visible from the outside — not that your internal network, the application behind the login or your other domains are in order, and not that a legal or contractual requirement has been met. For the domain and website checks, the queries reach the target from our infrastructure and their number is capped, so they cannot be used to quietly probe someone else's systems. Nothing passes through our infrastructure for the password check or the generator; the file check sends only a hash, never the file itself, and the address check sends only a hash to the breach database — our server needs the address itself solely to send the verification link to it.
Content valid as of 8 August 2026

Need to go through more than one place?

Six checks show six
points. An assessment
shows the whole.

A quick check is a good start. When you need to know how the environment stands as a whole, the website and the infrastructure behind it can be gone through as part of a security assessment.