FREE HOSTNAME CHECK

Check your public exposure.

Ten checks of one public hostname. No account or email required.

Use a hostname you own or are authorized to check, such as example.com.

Read the findings and download your result. No account needed.

How this check works

Enter only the hostname, without https://, a path or a port. WitnessOps servers make ten bounded public DNS, TLS and HTTP observations. No exploitation or credentials; web connections use ports 80/443 only. Results stay in this page until you clear or leave it. This feature does not store results.

What gets checked

  • Connection security

    Where the hostname points and how it connects.

    Public DNS target · TLS certificate · Legacy TLS
  • Web configuration

    How the site handles HTTPS and public security information.

    HTTPS redirect · HSTS · Response headers · security.txt
  • Email & certificate policy

    Published policies for email senders and certificate issuers.

    SPF · DMARC · CAA
Scope and limitations

This snapshot covers ten defined public observations against the submitted hostname at the recorded time. It does not establish the absence of vulnerabilities and does not constitute a penetration test, complete attack-surface assessment, certification, compliance assessment, or assurance opinion.

  • Application vulnerability exploitation
  • Authenticated functionality
  • Credentials and brute force
  • Ports other than 80/443
  • Internal infrastructure
  • Cloud/IAM configuration
  • Complete subdomain discovery
  • Agent permissions and internal controls
  • Malware
  • Full TLS/cipher audit
  • Complete mail architecture
External Exposure Snapshot | WitnessOps