Free tool

Run a free security scan.
See what the internet sees.

Your domain is looked at from the outside every day: by attackers mapping targets, and increasingly by insurance carriers pricing cyber policies. A free security scan shows you that outside view in about a minute. 15 external checks, one A to F grade, specific fixes. No signup, no agents, no sales call.

Scan modules15
Ports checked17
Reputation lists22
Scan time< 1 min
CostFree
How the platform works
External, non-exploitative scanning only
Data encrypted in transit and at rest
15 scan modules per scan
Results typically in under a minute
OpenAPI 3.1 specification
Coverage

Everything an external scan sees

One scan runs 15 modules against a domain you own or are authorized to assess, all from the outside. No agents, no credentials, nothing to deploy.

SSL/TLS
DNS & Email Security
DNSSEC
HTTP Security Headers
Open Ports
WHOIS
Blacklists
Cookie Security
Subdomain Exposure
Technology Fingerprint
WAF Detection
Breach Exposure
IP Reputation
JavaScript Security
Tracker Analysis
15
Scan modules
17
High-signal ports
22
Reputation lists
<60s
Full scan
Why it matters

The outside view is the one used against you

Attackers scan from outside

Nobody attacking your network starts with your internal tooling. They start with what your domain exposes publicly. A free external scan shows you the same map they see, so nothing on it surprises you.

  • Open ports and stale subdomains
  • Missing authentication records
  • Expired or weak certificates

Insurers scan from outside

Cyber insurance carriers increasingly price policies partly on what an external scan of the domain turns up. The first time most companies see those results is when the quote arrives. Scanning yourself first flips that order.

  • Exposed RDP is a common red flag
  • Email auth gaps affect pricing
  • See the list before underwriting does

MSPs get graded from outside

If you manage IT for clients, their external posture is your report card, whether or not you agreed to that. Scan client domains before quarterly reviews and renewals so that when something needs fixing, you found it first.

  • 10 free scans a month per account
  • $99/mo covers 1,000 across a book
  • Client-ready graded reports
FAQ

Free security scan questions

Is a free security scan actually free?

Yes. The scan at compliancelayer.net/check runs without an account, a credit card, or a sales call. If you want to keep scanning on a schedule or via API, a free account includes 10 scans per month, and paid plans start at $99/mo for 1,000 scans. The free scan is the product, not a teaser: you get the real grade and the real findings.

Am I allowed to scan any domain?

No, and a scanner that lets you should worry you. You may scan domains you own or are authorized to assess, for example as the IT provider under contract. The scan asks you to confirm this before it runs, and our Acceptable Use Policy explains the rule. External checks use information a domain already exposes publicly, but assessing someone else’s security posture without authorization is not appropriate, so we require the confirmation.

What does the free security scan check?

Fifteen external modules: SSL/TLS certificate health, DNS configuration and email authentication (SPF, DKIM, DMARC, DNSSEC), open ports across 17 high-signal services like RDP and SMB, HTTP security headers, breach exposure, blacklist status across 22 reputation lists, subdomain exposure, WAF detection, and more. Everything is checked from the outside, with no agents to install and no credentials to hand over.

How long does it take?

Typically under a minute. You enter a domain, confirm you are authorized to scan it, and get an A to F grade with per-category scores and specific remediation steps while you wait.

Is this the same as a vulnerability scan or penetration test?

No. A penetration test is a human actively trying to break in, and an authenticated vulnerability scan inspects systems from the inside. This is an external posture scan: it evaluates what your domain exposes to anyone on the internet, which is also roughly what cyber insurance carriers look at when they assess a domain during underwriting. It complements internal tools; it does not replace them.

Why does my security grade matter for cyber insurance?

Carriers and underwriters increasingly run external scans of a domain as an input to pricing and renewing cyber policies. Things like exposed RDP, missing email authentication, or expired certificates can show up on that scan before anyone inside the company knows. Running your own scan first means you see the list before the insurer does, and can fix findings before they become premium increases or coverage questions.

Want the methodology? Read how the scan works, or review the Acceptable Use Policy that governs every scan.

Get started

Start scanning your first
domain in 60 seconds.

No credit card. No sales call. No setup. The free tier is here to stay.

10 free scans per monthAPI key in 30 secondsCancel anytime

All scans are external and non-exploitative — we never access your servers, install agents, or require credentials. View our security practices, or live system status.