Free 60-second domain scan · no signup
See what they found. Free scan, results in about 60 seconds.
free scan · no signup · ~60s
Works with sites built on
Same free outside-in scan for every stack. No plugin or account connect required.
Why it matters
DNS, email auth, headers, certificates, and exposure signals are easy to check from the internet. RedScore turns that into a score and a short priority list so you are not the last to know.
Built for operators
Everything you need to see how your domain looks from the outside, without opening ten browser tabs.
Enter a domain and get a public attack-surface view in about 60 seconds. No account required.
DNS, email, web, exposure, certificates, and more rolled into letter grades you can act on.
A short AI summary ranks what failed, why it matters, and what to tackle first.
Verify domain ownership to turn one-off scans into alerts and ongoing posture tracking.
What you get
One scan rolls DNS, email, web, exposure, and related checks into grades you can act on, not a pile of raw tabs.
63 / 100
Grade C
example-corp.com
AI summary
Cookie settings are weak and server headers reveal stack details. Email spoofing is plausible with incomplete SPF and DMARC.
What scans usually surface
These are typical patterns from real check types, not customer stories. Your scan may surface different items, but email auth and header gaps show up often.
RedScore Pro
The free scan grades DNS, email auth, TLS, and headers anyone can see from the outside. Pro adds exposed services, secrets in JS bundles, CVE signals, and the watching layer: custom cadence, Ray guidance, trends, PDFs, and team alerts when something slips.
See your public score, ten letter grades, and a plain-English summary. No account.
Scan a domainVerify ownership to unlock full findings, scheduled scans, and email when something changes.
Unlock exposed services, JS secrets, CVE checks, Ray guidance, trends, PDFs, and team alerts on regressions.
Pro scan modules
Find open ports and services that should be closed, filtered, or reviewed.
Look for tokens, keys, and sensitive config accidentally shipped to the browser.
Match visible software signals against known vulnerability data.
Check common public paths for admin panels, backups, and stray files.
AWS posture, code security, and additional active checks are coming.
Pro preview
Deeper scans + watchingCredential pattern in a public bundle
Sensitive value in client-side code
Found in a public JavaScript bundle
Pro surfaces secrets shipped to the browser. Claim to see exact locations.
New exposed service on next scan
A service appeared that was not there last week. RedScore flagged it on the scheduled run.
Score recovered after the exposed service was closed.
Known CVE matched to a visible software signal.
Upgrade the affected component.
Retest after deploy to confirm the finding clears.
Pro adds step-by-step fix notes per finding.
Claim your domain for full findings. Pro unlocks deeper modules and keeps watching.
Set weekly or monthly scans, pause a domain, and pick which modules run. Email alerts on every run.
Site-specific fix notes on each finding after scans complete. Priority and sequencing that fit your stack.
Track score and finding changes over time so you know whether a change worked or something regressed.
Pricing
Free scan
One outside-in snapshot of any domain.
Claimed
Turn a one-off scan into ongoing visibility for domains you own.
RedScore Pro
Deeper scans plus watching, guided fixes, and proof for customers and stakeholders.
The difference
SecurityScorecard and Bitsight are built for enterprise procurement. RedScore gives teams the same outside-in view without a sales cycle.
Outside-in domain scan
Letter grades + 0-100 score
Category breakdown
Plain-English summary
Signup to try
Enterprise tools: $25k+/yr
RedScore: Free
Enterprise pricing varies by contract. See full comparison
Go further with Pro
Get finding-specific fix notes and next steps after each scan completes.
Create PDF reports for stakeholders and publish a curated trust page for customers.
Send scan updates to Slack, Discord, webhooks, and email so fixes reach the right team.
FAQ
Free scan · No signup · ~60 seconds