ThreatScout by ScoutLabFree Website Security Checker
Run a free website security scan to check your website's publicly visible security configuration, including HTTPS, security headers, DNS and email protection. No installation or server access required.
- No account required
- Nothing to install
- No server access needed
What does our website security checker scan?
The free scan reviews publicly accessible security signals and configuration issues. It runs from the outside only — nothing is installed and no access to your server is needed.
HTTPS and TLS configuration
Whether your website is reachable over HTTPS, whether the connection responds correctly, and whether certificate details can be assessed from outside.
Security headers
Whether commonly recommended headers are returned — HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options and Referrer-Policy.
Read our security headers guideDNS and domain configuration
Whether your domain resolves as expected and how its public records are configured.
Email protection records
Whether SPF, DKIM and DMARC records are published for your domain, and whether a DMARC policy is enforced.
Learn how SPF, DKIM and DMARC work togetherWebsite configuration issues
Configuration responses that differ from commonly recommended settings for modern websites.
Publicly visible weaknesses
Signals that are already exposed to the internet and may add avoidable risk to your website.
Understand your website's security posture
A ThreatScout security score
A 0–100 score summarising how your website's publicly visible security signals compare with commonly recommended configuration.
A summary of what was detected
The issues found during the scan, grouped and described in plain English so a non-technical owner can follow along.
A clear starting point
An indication of which areas deserve attention first, so you can raise them with whoever looks after your website.
Types of findings ThreatScout may identify
These are explanatory examples of the kinds of issues an external scan can surface. Not every scan will find these, and your results depend entirely on your own website.
Missing security headers
Security protections recommended for modern websites may not be configured.
TLS configuration issues
Older or weaker encryption settings may still be publicly available.
Website exposure
Externally visible services or configuration may increase the website's attack surface.
Email protection gaps
SPF, DKIM or DMARC records may be missing or not enforced for the domain.
Why scan your website?
A website that was configured correctly a year ago may look different to the internet today. Websites change over time, and so do the signals they publish.
How to check your website security
You do not need technical access to get a first view of your website's external security posture.
Enter your business domain
Provide the website you are responsible for. Nothing is installed and no hosting or CMS access is required.
Run the free website security check
ThreatScout reviews the publicly visible security signals your website and domain already expose to the internet.
Review your score and findings
See your ThreatScout score and a plain-English summary of the areas detected, so you know what may deserve attention.
Website security scan vs website vulnerability assessment
Free website security scan
An initial external review of the publicly visible website and domain security signals your site already exposes. You receive a ThreatScout score and a summary of the findings detected, giving you a free starting point for understanding where to look next.
Website vulnerability assessment
A deeper external assessment with expanded attack-surface and security-signal coverage where applicable, surfacing broader findings for investigation and prioritisation. It is a paid assessment, and neither the free scan nor the vulnerability assessment is equivalent to a comprehensive manual penetration test.
For ongoing visibility after your first assessment, learn about website security monitoring.
Free website security scan questions
Is the website security scan really free?
+
Yes. The ThreatScout free scan costs nothing and no payment details are required. You enter your website details, the scan runs, and you receive your ThreatScout score and a summary of what was detected.
Do I need to install anything?
+
No. ThreatScout runs entirely from the outside, the same way a visitor or an attacker would see your website. There is nothing to install, upload or configure.
Do I need access to the website server?
+
No. The free scan only reviews information that is already publicly available, such as your website's HTTPS response, security headers and public DNS records. You do not need server, hosting or CMS access.
What does the security score mean?
+
The ThreatScout score is a 0–100 indicator of how your website's publicly visible security signals compare with commonly recommended configuration. Higher is better: 90 and above is low risk, 75–89 moderate, 50–74 elevated, and below 50 high risk.
Is this the same as a penetration test?
+
No. A penetration test is a manual, in-depth engagement that actively attempts to exploit weaknesses. The ThreatScout free scan is an automated review of publicly accessible security signals and configuration. It is a starting point, not a replacement for a penetration test.
Can the scan guarantee my website is secure?
+
No. A good score means the publicly visible signals we check look healthy. It cannot prove a website is secure, because many risks are not visible externally. Treat the results as an indication of where to look next.
How can I check my website security online?
+
Start with an external website security check that reviews the signals your website already publishes to the internet, such as HTTPS, security headers, public DNS and email protection records. ScoutLab's free website security checker performs those checks without installing anything or requiring server access.
What does a website security checker look for?
+
ScoutLab's free checker reviews externally visible signals including HTTPS and certificate response, recommended security headers, public DNS and domain records, and SPF, DKIM and DMARC email protection records. It is an external configuration assessment, not a manual penetration test.
Ready to see where your website stands? Run the free scan or learn more about website vulnerability assessments.
