Scan your domain and discover security weaknesses in minutes - no account required.
SPF, DKIM, DMARC and MX configuration - the controls that stop attackers spoofing your domain.
HTTPS, TLS certificate health, and the security headers browsers rely on.
DNSSEC, CAA, and domain registration status - including expiry, which businesses genuinely lose domains to.
Subdomains and infrastructure that are publicly discoverable through legitimate, passive sources.
Whether your mail servers are currently listed on spam blocklists that could be silently rejecting your email.
No account, no sign-up wall - just the domain name. Takes five seconds.
13+ checks across email, website, domain, exposure, and reputation - all from the same public sources anyone (attacker included) could already query.
A score out of 100, exactly what we found, why it actually matters for your business, and how to fix it - plus a downloadable PDF.
Not a jargon dump. Every issue we flag comes with the business risk in plain English, a concrete fix, and the raw evidence behind it - these are real examples from an actual scan (domain replaced with a placeholder).
{
"recordsFound": 0,
"checked": "_dmarc.acmewidgets.co.uk"
}{
"subdomains": [
"admin.acmewidgets.co.uk",
"vpn.acmewidgets.co.uk",
"staging-old.acmewidgets.co.uk"
],
"source": "certificate transparency logs"
}No. Domain Medic runs automated, passive checks against publicly accessible information - DNS records, response headers, certificate data. It never attempts to log in, exploit anything, or access systems that aren't already public. It complements a penetration test; it isn't a substitute for one.
No. Every check is read-only - the same kind of request a browser makes when it visits your site, or a DNS lookup anyone can run. Nothing is modified, nothing is written to, nothing is submitted.
Typically under 10 seconds. All checks run concurrently rather than one after another.
Every finding that needs attention comes with a plain-English ‘why this matters’ and a concrete ‘how to fix it’ - not just a technical label. See the example below.
Payment is processed entirely by Stripe - we never see or store your card details. We keep only what's needed to show you your report: the domain scanned and the results. See our Privacy Policy for the full detail.
Only scan domains you own or are explicitly authorised to assess. Every check here only touches publicly available information, but the results can reveal real weaknesses - treat that responsibly.