Spoofhound

Website security scanner

Enter a website to check its HTTPS and HSTS setup, security headers, Content-Security-Policy, mixed content and third-party script integrity, cookie flags, version disclosure, exposed .env/.git paths, DNSSEC and CAA, and its security.txt — with a grade out of 100 and exactly what to fix.

Scans are run from Spoofhound's network against the address you enter, reading only the site's front page and a couple of well-known paths — no login, no crawling. Results reflect what we could see from the outside; a check we couldn't run is marked as such and left out of the score.