Truvo Free Tools
Check your domain's external security posture
Your domain's public configuration is the first thing an attacker, a customer's security team or an auditor looks at. This scan reads it in one pass across email authentication, DNS, TLS, HTTP security headers and subdomain footprint, grades it A to F, and names the SOC 2 and ISO 27001 control each finding relates to.
Ali Aleali, CISSP, CCSP
Co-Founder & Principal Consultant
Former security architect for Bank of Canada and Payments Canada. 20+ years building compliance programs for critical infrastructure. These tools come out of that work.
Connect on LinkedInHow the domain security scan works
The scan is passive: it reads public DNS records over DNS over HTTPS, makes one normal HTTPS request and one HTTP request to your homepage, and searches public Certificate Transparency logs, and it never probes your systems.
01
Query
You enter a domain. The tool reads its public DNS records (MX, SPF, DMARC, MTA-STS, nameservers, CAA, DNSSEC), requests the homepage once over HTTPS and once over HTTP, and searches Certificate Transparency logs for hostnames under the domain.
02
Read
Findings are grouped in five areas: email authentication, DNS hygiene, TLS and HTTPS, HTTP security headers, and subdomain footprint. Each finding says what was found, why it matters and how to fix it, and the whole result is graded A to F.
03
Map
Every finding names the SOC 2 criterion and ISO 27001:2022 Annex A control it gives evidence for or signals a gap against, so you know which audit question a fix answers. The single-check tools below run one area at a time.
Found a gap? We fix it for you.
Truvo's security engineers harden mail, DNS, TLS and web configuration, and hand you the evidence an auditor asks for. Tell us the domain and we will scope the fix.
-
Email authentication
-
DNS hygiene
-
TLS and HSTS
-
Security headers
-
Asset inventory
-
Audit evidence
Domain security scan: frequently asked questions
Five areas of your domain's public configuration: email authentication (MX, SPF, DMARC and MTA-STS), DNS hygiene (nameserver redundancy, CAA and DNSSEC), TLS and HTTPS (reachability, redirect and HSTS), HTTP security headers (CSP, clickjacking protection, MIME sniffing, referrer and permissions policies, server banner) and subdomain footprint (Certificate Transparency enumeration and non-production host detection).
Yes. Every check reads public data: DNS records, one normal web request to the homepage, and Certificate Transparency logs. Nothing is probed, written or changed. Running it on a vendor's domain reads the same public information their customers and any attacker can already see.
Each of the five areas starts at 100 and loses points for every finding according to its severity, and the combined result is shown as a letter from A to F. In the email area a missing SPF or DMARC record costs the most, while optional hardening such as MTA-STS costs little. The grade is a quick read of external posture, not a compliance verdict.
Each finding names the SOC 2 Trust Services Criteria and the ISO 27001:2022 Annex A control it relates to, for example CC6.7 and A.5.14 for email authentication or A.8.24 for TLS. The mapping is advisory: it shows which control a finding gives evidence for or signals a gap against. It is not a substitute for an audit.
No. Enter a domain and the full result appears in seconds. You can optionally leave an email to receive the report, or to ask us to help with what the scan found.
More free tools
Run a single check on its own. See all free tools.
SPF record checker
Validate your SPF record, catch lookup-limit and syntax problems, and see whether spoofed mail can pass as you.
SSL and TLS checker
Test HTTPS reachability, the HTTP to HTTPS redirect, and HSTS strength for any domain.
Subdomain finder
Enumerate subdomains from Certificate Transparency logs and spot staging or legacy hosts you forgot about.