Have the whole website handled
Build or migrate the site, then keep hosting, security, monitoring, and updates with one accountable engineer.
Managed website service →Free security scan
Enter your domain and get an instant, plain-English setup grade for your certificate, protective headers, email spoofing policy, DNS, and edge protection. No signup and nothing installed.
Type your domain without https:// — for example acmedental.com. Identical-domain results may be cached briefly to prevent abuse; nothing becomes a customer record unless you contact us or create a shareable report.
What this checks
This scan reads only public information and never touches your systems. It's a starting point, not a full audit — but every red mark is a real gap worth closing.
Before you scan
Yes. The scan reads only information your site already publishes to every visitor — your certificate, your DNS records, your response headers. It never logs in, never submits forms, and never touches your server beyond loading it the way a normal browser would. It cannot slow down or break anything.
Not as a customer record. Identical-domain results may be cached for up to 10 minutes to prevent abuse and repeated third-party lookups. A report snapshot is stored for 90 days only when you explicitly create a shareable link.
Because the attack never touches your website. A sender can place your domain in the visible From address, then rely on weak or missing authentication policy to improve the odds that the message is accepted. An enforcing DMARC policy materially reduces that risk, although each receiving provider still applies its own local security policy.
Your report lists findings in priority order — problems first, ranked by severity. Broadly: a broken secure connection and a missing domain spoofing policy outrank optional hardening, followed by protective headers and the domain transfer lock. Every finding explains what it is and how it gets fixed — by you or by us.
No, and be wary of any instant tool that claims to be. This grades your public-facing configuration — the locks on the doors. It can't see your website's code or plugins, and it can't tell whether the site has already been compromised. It's the right place to start because most small-business sites fail at least one of these fundamentals.