Truvo Free Tools
Check your domain's external security posture
See what an attacker sees first: mail records, DNS, HTTPS, browser defences and forgotten subdomains, graded A to F and mapped to the SOC 2 and ISO 27001 controls each one affects.
What the scan checks
Five areas of passive checks, each mapped to the SOC 2 Trust Services Criteria and ISO 27001:2022 Annex A controls it gives evidence for. Read the field manual.
Email authentication
MX hosts and redundancy, SPF policy, DMARC enforcement, MTA-STS.
DNS hygiene
Nameserver redundancy, CAA records restricting certificate issuance, DNSSEC signing.
TLS and HTTPS
HTTPS reachability, HTTP to HTTPS redirect, HSTS policy strength.
HTTP security headers
Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy.
Subdomain footprint
Subdomain enumeration from Certificate Transparency, flagging staging and legacy hosts.
From scan to audit evidence
Every control chip opens the control text, suggested evidence and Trust Services Category in the Compliance Framework Explorer. Free, no sign-up.
Every check is passive and based on publicly observable data. Nothing is sent to non-public endpoints and nothing on your systems is changed. A scan usually completes in under ten seconds.
Ali Aleali, CISSP, CCSP
Co-Founder & Principal Consultant, built Truvo Exposure
Former security architect for Bank of Canada and Payments Canada. 20+ years building compliance programs for critical infrastructure. These tools come out of that work.
Connect on LinkedInHow the domain security scan works
The scan is passive: it reads public DNS records over DNS over HTTPS, makes one normal HTTPS request and one HTTP request to your homepage, and searches public Certificate Transparency logs, and it never probes your systems.
01
Query
You enter a domain. The tool reads its public DNS records (MX, SPF, DMARC, MTA-STS, nameservers, CAA, DNSSEC), requests the homepage once over HTTPS and once over HTTP, and searches Certificate Transparency logs for hostnames under the domain.
02
Read
Findings are grouped in five areas: email authentication, DNS hygiene, TLS and HTTPS, HTTP security headers, and subdomain footprint. Each finding says what was found, why it matters and how to fix it, and the whole result is graded A to F.
03
Map
Every finding names the SOC 2 criterion and ISO 27001:2022 Annex A control it gives evidence for or signals a gap against, so you know which audit question a fix answers. The single-check tools below run one area at a time.
Found a gap? We fix it for you.
Truvo's security engineers harden mail, DNS, TLS and web configuration, and hand you the evidence an auditor asks for. Tell us the domain and we will scope the fix.
-
Email authentication
-
DNS hygiene
-
TLS and HSTS
-
Security headers
-
Asset inventory
-
Audit evidence
Domain security scan: frequently asked questions
Five areas of your domain's public configuration: email authentication (MX, SPF, DMARC and MTA-STS), DNS hygiene (nameserver redundancy, CAA and DNSSEC), TLS and HTTPS (reachability, redirect and HSTS), HTTP security headers (CSP, clickjacking protection, MIME sniffing, referrer and permissions policies, server banner) and subdomain footprint (Certificate Transparency enumeration and non-production host detection).
Yes. Every check reads public data: DNS records, one normal web request to the homepage, and Certificate Transparency logs. Nothing is probed, written or changed. Running it on a vendor's domain reads the same public information their customers and any attacker can already see.
Each of the five areas starts at 100 and loses points for every finding according to its severity, and the combined result is shown as a letter from A to F. In the email area a missing SPF or DMARC record costs the most, while optional hardening such as MTA-STS costs little. The grade is a quick read of external posture, not a compliance verdict.
Each finding names the SOC 2 Trust Services Criteria and the ISO 27001:2022 Annex A control it relates to, for example CC6.7 and A.5.14 for email authentication or A.8.24 for TLS. The mapping is advisory: it shows which control a finding gives evidence for or signals a gap against. It is not a substitute for an audit.
No. Enter a domain and the full result appears in seconds. You can optionally leave an email to receive the report, or to ask us to help with what the scan found.
More free tools
Run a single check on its own. See all free tools.
SPF record checker
Validate your SPF record, catch lookup-limit and syntax problems, and see whether spoofed mail can pass as you.
SSL and TLS checker
Test HTTPS reachability, the HTTP to HTTPS redirect, and HSTS strength for any domain.
Subdomain finder
Enumerate subdomains from Certificate Transparency logs and spot staging or legacy hosts you forgot about.