Is a free security scan actually free?
Yes. The scan at compliancelayer.net/check runs without an account, a credit card, or a sales call. If you want to keep scanning on a schedule or via API, a free account includes 10 scans per month, and paid plans start at $99/mo for 1,000 scans. The free scan is the product, not a teaser: you get the real grade and the real findings.
Am I allowed to scan any domain?
No, and a scanner that lets you should worry you. You may scan domains you own or are authorized to assess, for example as the IT provider under contract. The scan asks you to confirm this before it runs, and our Acceptable Use Policy explains the rule. External checks use information a domain already exposes publicly, but assessing someone else’s security posture without authorization is not appropriate, so we require the confirmation.
What does the free security scan check?
Fifteen external modules: SSL/TLS certificate health, DNS configuration and email authentication (SPF, DKIM, DMARC, DNSSEC), open ports across 17 high-signal services like RDP and SMB, HTTP security headers, breach exposure, blacklist status across 22 reputation lists, subdomain exposure, WAF detection, and more. Everything is checked from the outside, with no agents to install and no credentials to hand over.
How long does it take?
Typically under a minute. You enter a domain, confirm you are authorized to scan it, and get an A to F grade with per-category scores and specific remediation steps while you wait.
Is this the same as a vulnerability scan or penetration test?
No. A penetration test is a human actively trying to break in, and an authenticated vulnerability scan inspects systems from the inside. This is an external posture scan: it evaluates what your domain exposes to anyone on the internet, which is also roughly what cyber insurance carriers look at when they assess a domain during underwriting. It complements internal tools; it does not replace them.
Why does my security grade matter for cyber insurance?
Carriers and underwriters increasingly run external scans of a domain as an input to pricing and renewing cyber policies. Things like exposed RDP, missing email authentication, or expired certificates can show up on that scan before anyone inside the company knows. Running your own scan first means you see the list before the insurer does, and can fix findings before they become premium increases or coverage questions.