Truvo Free Tools

Check your domain's external security posture

Your domain's public configuration is the first thing an attacker, a customer's security team or an auditor looks at. This scan reads it in one pass across email authentication, DNS, TLS, HTTP security headers and subdomain footprint, grades it A to F, and names the SOC 2 and ISO 27001 control each finding relates to.

SOC 2 CC6.1SOC 2 CC6.7SOC 2 CC7.1ISO 27001 A.5.14ISO 27001 A.8.20ISO 27001 A.8.24
Ali Aleali

Ali Aleali, CISSP, CCSP

Co-Founder & Principal Consultant

Former security architect for Bank of Canada and Payments Canada. 20+ years building compliance programs for critical infrastructure. These tools come out of that work.

Connect on LinkedIn

How the domain security scan works

The scan is passive: it reads public DNS records over DNS over HTTPS, makes one normal HTTPS request and one HTTP request to your homepage, and searches public Certificate Transparency logs, and it never probes your systems.

01

Query

You enter a domain. The tool reads its public DNS records (MX, SPF, DMARC, MTA-STS, nameservers, CAA, DNSSEC), requests the homepage once over HTTPS and once over HTTP, and searches Certificate Transparency logs for hostnames under the domain.

02

Read

Findings are grouped in five areas: email authentication, DNS hygiene, TLS and HTTPS, HTTP security headers, and subdomain footprint. Each finding says what was found, why it matters and how to fix it, and the whole result is graded A to F.

03

Map

Every finding names the SOC 2 criterion and ISO 27001:2022 Annex A control it gives evidence for or signals a gap against, so you know which audit question a fix answers. The single-check tools below run one area at a time.

Found a gap? We fix it for you.

Truvo's security engineers harden mail, DNS, TLS and web configuration, and hand you the evidence an auditor asks for. Tell us the domain and we will scope the fix.

  • Email authentication

  • DNS hygiene

  • TLS and HSTS

  • Security headers

  • Asset inventory

  • Audit evidence

Domain security scan: frequently asked questions

Five areas of your domain's public configuration: email authentication (MX, SPF, DMARC and MTA-STS), DNS hygiene (nameserver redundancy, CAA and DNSSEC), TLS and HTTPS (reachability, redirect and HSTS), HTTP security headers (CSP, clickjacking protection, MIME sniffing, referrer and permissions policies, server banner) and subdomain footprint (Certificate Transparency enumeration and non-production host detection).

Yes. Every check reads public data: DNS records, one normal web request to the homepage, and Certificate Transparency logs. Nothing is probed, written or changed. Running it on a vendor's domain reads the same public information their customers and any attacker can already see.

Each of the five areas starts at 100 and loses points for every finding according to its severity, and the combined result is shown as a letter from A to F. In the email area a missing SPF or DMARC record costs the most, while optional hardening such as MTA-STS costs little. The grade is a quick read of external posture, not a compliance verdict.

Each finding names the SOC 2 Trust Services Criteria and the ISO 27001:2022 Annex A control it relates to, for example CC6.7 and A.5.14 for email authentication or A.8.24 for TLS. The mapping is advisory: it shows which control a finding gives evidence for or signals a gap against. It is not a substitute for an audit.

No. Enter a domain and the full result appears in seconds. You can optionally leave an email to receive the report, or to ask us to help with what the scan found.