Find what an attacker would find — before they do.
CheckIntruder scans your domain's DNS, SSL certificate, security headers, and open ports — then walks you through the results in plain English. No dashboard to learn, no jargon. Just talk to it like a colleague who happens to know security.
From domain name to plain-English answer, in four steps.
Enter your domain
Type in the domain you want checked. No account needed to see what's involved.
Prove it's yours
Add one TXT record to your DNS. Takes about two minutes, confirms instantly.
Talk to the scanner
Chat through the findings in plain English. Ask follow-up questions — not a wall of red and yellow icons.
Go deeper if you need to
Add an advanced external audit, an internal audit, or a prioritized fix list — pay only for what you check off.
A focused scan, not a noisy wall of findings.
DNS configuration
Records, delegation, and the common misconfigurations that leak more than they should.
SSL / TLS certificate
Expiry, protocol strength, and whether your certificate chain actually holds up.
HTTP security headers
The headers browsers check before trusting your site — and exactly what's missing.
Open ports
A focused check of the ports that actually matter — not a noisy full sweep.
A security check you keep in your toolbox, not a product you have to manage.
Freelancers & consultants
Hand a client a real, credible finding in minutes — without billing a security engagement to get there.
IT & sysadmin teams
A fast second opinion before a launch, a migration, or a client asking "are we exposed?"
Agencies & small teams
Check every site you ship as part of the job, not as a separate line item nobody wants to pay for.
Start free. Pay only for what you check off.
DNS, TLS, headers, and open-port checks with a plain-English report. No card required.
Start free scanAdvanced external checks plus an internal audit — the full picture, verified in one pass.
Verify your domainA prioritized fix list for whatever the scan turns up, ready to bring straight into a team meeting. Works on top of the free scan or the deep audit.
Add to a scanNeed real internal access, patching, and compliance sign-off?
Some engagements go beyond what an automated scan can responsibly do — real infrastructure access and patching, and unannounced red-team exercises against your blue team using a wide range of adversarial techniques (including DDoS resilience testing), with rules of engagement agreed with leadership in advance and timing kept a surprise to defenders. We also handle audits aimed at compliance certifications like SOC 2 or ISO 27001 — all scoped and carried out by our team under your explicit, documented authorization, never self-serve, never automated.
Running financial services, industrial, or large corporate infrastructure?
Common Criteria (ISO/IEC 15408) audits and custom compliance engagements for financial-services, industrial, and enterprise environments — scoped to your regulatory requirements, with findings documented for executive and board-level review. Budget and timeline are quoted per engagement.