Free check

How does yourbusiness lookfrom out here?

A quick security and infrastructure check on any domain. No cost, no sign-up, no sales call attached. It reads what is already public and tells you the three things we would fix first.

imp@purpleimp.it: ~
ready. type a domain and press enter.

Type a domain.

Yours, or one you are responsible for. Please don't run it against domains that aren't anything to do with you.

Everything here is what anyone on the internet can already see about your domain:

  • DNS: does the domain resolve to a public address
  • SSL: is the certificate valid, and when does it expire
  • HTTPS: does plain http redirect, is HSTS on
  • Headers: the basic security headers, and version banners
  • Email: MX, SPF, DMARC policy, DKIM at common selectors
  • CAA: who is allowed to issue your certificates

What it can't see: backups, MFA, patching, who still has the admin password. That's the conversation.

What the results mean

DNS

Whether the domain points anywhere reachable. If this fails, nothing else can work, and it is usually an expired domain or a record pointing at a server that no longer exists.

SSL certificate

Valid, and how long until it expires. Under a fortnight is worth attention: it suggests renewal is manual, and manual renewals get missed.

HTTP to HTTPS

Whether plain, unencrypted http redirects to the secure version. If it does not, some visitors browse your site unencrypted without ever knowing.

HSTS

A header telling browsers to only ever use the secure version of your site in future. It closes a gap that redirects alone leave open.

Security headers

Five standard headers that stop whole classes of attack. They take minutes to add and most sites have none of them.

Version banners

Whether your server announces exactly which software versions it runs. That tells an attacker precisely which holes to try.

MX

Where your email is handled. We report the provider, and nothing about your actual mail.

SPF

The record listing who is allowed to send email as you. Missing, duplicated or too permissive are all common, and all mean it is not protecting you.

DMARC

What receiving servers should do with mail that fails the checks. Most domains have it set to "do nothing and tell me" and never move past that.

DKIM

A signature proving mail really came from you. We look at the usual selector names; not finding one is not proof it is missing.

CAA

Which certificate authorities are allowed to issue certificates for your domain. Optional, but it closes a door.

The fixes

The three we would start with, in order. You are welcome to take the list to whoever looks after your systems. It is not a trap.

Being straight about the limits

What it can't tell you.

This is a first look from the outside, not an audit. It reads public records and response headers. It never logs into anything, and it never sees your data.

  • Whether your backups work. Nothing outside your network can see that. Only a tested restore can.
  • Whether multi-factor authentication is on. Or who still has an administrator account.
  • Whether your software is patched. We can see the versions you advertise, which is not the same thing.
  • Whether you have already been breached. A clean result means the front door looks sound today.

Fine print, in short

We log the domain checked, the time, and a shortened one-way hash of your IP address so the tool cannot be abused, and we delete those logs after 14 days. There is no sign-up, we do not email you afterwards, and results are cached for ten minutes so a repeat check may show the same answer. Full detail is on the privacy page.

Found something you did not like?

We can fix that.

Send us the result, or just tell us which line bothered you. No obligation, and no sales sequence.