Free tool · Public DNS + one page request

What your public surface tells anyone who looks

Two signals anyone can read without your permission: the DNS that says who may send mail as you, and the headers your homepage returns to every visitor. This reads both and returns them as a short list of prioritized findings — not a checklist score, and not a hundred rows for you to triage.

Free · No card · No login · Public signals only

Check your own domain

Enter a domain. Warden reads its public DNS and requests its homepage once, then returns what it found in priority order — each finding with the observation that produced it and one recommended action. Ranked by reachability, exploitability and business relevance, not by a score.

Reads public TXT and MX records and one HTTPS request to the homepage, headers only. No port scanning, no paths guessed, no payloads, no login attempted, nothing inside your systems touched. The domain you enter is not added to any list.

How the ranking is decided

A finding earns its place by argument, not by a number handed down from a severity table. Three questions decide the order, and each finding says which of them carried it.

The same three criteria order the findings inside a paid Snapshot. This tool is the automated slice of that method, run on the two signals that can be read without authorization.

Limits, stated plainly

Questions this raises

What does this check actually read?

Two public signals. Public DNS: the SPF chain, every include it resolves, and the DMARC record at _dmarc.yourdomain. And one HTTPS GET of your homepage, from which only the response headers are used — transport security, content policy, framing, referrer policy, software banners and cookie attributes. The page body is discarded.

Is this a scan of my systems?

No. It reads DNS that any receiving mail server reads at delivery time, and makes one ordinary request for the homepage the way any visitor's browser does. No ports are probed, no paths are guessed, no payloads are sent and no login is attempted. Warden does not access, scan or investigate anything without agreed scope and explicit written authorization.

Why are the findings not ranked by CVSS?

Most of what this check surfaces has no CVE and therefore no CVSS score — a domain that permits anyone to send mail as it, or a redirect that never became HSTS. Warden ranks by whether a finding is reachable from outside, whether it is plausibly exploitable, and whether it is attached to something the business cares about. Each finding states which of the three carried it.

The check found nothing. Is that useful?

Yes, and it is reported as a result rather than padded. It means email authentication and the homepage response headers are configured the way they should be. It says nothing about authenticated application paths, dependencies or cloud configuration, because those are not readable from outside without authorization.

How is this different from the $299 Security Assessment Snapshot?

This check is automated, instant and limited to two public signals on one hostname. The Snapshot is a bounded engagement against a scope you agree and authorize in writing: it covers more of your public surface, and each finding is investigated rather than read off a header, with a governance note separating the recommendation from the authority to act. One-time, $299, no subscription.

Can I check a domain I do not own?

Technically yes, because everything it reads is public. Publishing findings about someone else's domain is a different matter, and Warden's own rule is that assessment work happens only against a scope its owner has authorized in writing.

Going deeper on one finding

If this check reported an SPF problem, the chain underneath it is worth counting properly: the lookup count against the RFC 7208 limit of 10, and the number of IPv4 addresses the chain authorizes to send as you. The SPF DNS lookup checker runs both and shows every record it read, and the teardown works through a real chain that authorized 1,086,996 addresses, in the order that reduces it without breaking your own mail.

Free · No card · No login

Free Exposure Check, researched by hand

This check reads two signals automatically. The free Exposure Check goes further by hand: three prioritized exposures on your public-facing product, each with the observable evidence that surfaced it, by email within 24 hours. Public information only — no scanning, no access to your systems. Free, no card, no login.

We use your email only to deliver your free check. No spam, no automated scanning of your systems, no unauthorized access.