RedScore.ai

Free 60-second domain scan · no signup

Attackers already
scanned you.

See what they found. Free scan, results in about 60 seconds.

free scan · no signup · ~60s

domains scanned
58checks per scan
~60savg scan time

Works with sites built on

  • WordPress
  • Shopify
  • Vercel
  • Netlify
  • Next.js
  • Cloudflare
  • Firebase
  • Supabase
  • Webflow
  • Squarespace
  • Wix
  • Framer
  • Google Cloud
  • Railway
  • DigitalOcean
  • Astro
  • Nuxt
  • Gatsby
  • Ghost
  • Drupal
  • BigCommerce
  • Laravel
  • Sanity
  • Remix
  • HubSpot
  • Contentful

Same free outside-in scan for every stack. No plugin or account connect required.

Why it matters

Your public footprint is not a secret

DNS, email auth, headers, certificates, and exposure signals are easy to check from the internet. RedScore turns that into a score and a short priority list so you are not the last to know.

Built for operators

One scan. Ten areas. Clear next steps.

Everything you need to see how your domain looks from the outside, without opening ten browser tabs.

Free outside-in scan

Enter a domain and get a public attack-surface view in about 60 seconds. No account required.

10 category grades

DNS, email, web, exposure, certificates, and more rolled into letter grades you can act on.

Fix priority, plain English

A short AI summary ranks what failed, why it matters, and what to tackle first.

Claim and monitor

Verify domain ownership to turn one-off scans into alerts and ongoing posture tracking.

What you get

One pass across your external attack surface

One scan rolls DNS, email, web, exposure, and related checks into grades you can act on, not a pile of raw tabs.

C62DNS & Domain Security
D48Email Security
B75Infrastructure Hygiene
C68Web Application Security
F32Cookie & Privacy Hygiene
D45Technology Fingerprinting
B78Public Exposure
A91Certificate & PKI Health
B82Brand & Domain Reputation
C55Third-Party Risk Surface
63/ 100
Grade C

63 / 100

Grade C

example-corp.com

AI summary

Cookie settings are weak and server headers reveal stack details. Email spoofing is plausible with incomplete SPF and DMARC.

Email auth gaps
Header hardening
Certificate hygiene

What scans usually surface

Common gaps on domains we check

These are typical patterns from real check types, not customer stories. Your scan may surface different items, but email auth and header gaps show up often.

DMARC in monitor-only mode

critical
What failed and why
DMARC is published with `p=none`, so failed mail is not blocked or quarantined.
Why this matters
Anyone can send email that looks like it came from your domain until you enforce policy.
Recommended fix
Move to `p=quarantine` or `p=reject` after reviewing DMARC reports for a week or two.

SPF too permissive

high
What failed and why
SPF allows too many senders or ends with `+all`, which weakens sender validation.
Why this matters
Spoofed mail can pass basic checks and reach inboxes that trust your domain name.
Recommended fix
Tighten SPF to only the servers that actually send mail for you, then retest.

Missing security headers

medium
What failed and why
Key HTTP headers like HSTS, CSP, or X-Frame-Options are absent on the public site.
Why this matters
Browsers get less protection against downgrade, clickjacking, and injection attacks.
Recommended fix
Add baseline headers at your CDN or web server, starting with HSTS and frame controls.

TLS or certificate hygiene gaps

medium
What failed and why
Certificate chain, expiry window, or TLS settings do not meet common hardening baselines.
Why this matters
Visitors and API clients may see trust warnings or weaker transport than they expect.
Recommended fix
Renew early, fix the chain, and disable legacy protocols on the edge.

RedScore Pro

Free scan covers public posture. Pro goes deeper.

The free scan grades DNS, email auth, TLS, and headers anyone can see from the outside. Pro adds exposed services, secrets in JS bundles, CVE signals, and the watching layer: custom cadence, Ray guidance, trends, PDFs, and team alerts when something slips.

01

Scan once

See your public score, ten letter grades, and a plain-English summary. No account.

Scan a domain
02

Claim and get alerts

Verify ownership to unlock full findings, scheduled scans, and email when something changes.

03

Pro goes deeper and keeps watching

Unlock exposed services, JS secrets, CVE checks, Ray guidance, trends, PDFs, and team alerts on regressions.

Pro scan modules

Exposed services

Find open ports and services that should be closed, filtered, or reviewed.

JS secret checks

Look for tokens, keys, and sensitive config accidentally shipped to the browser.

CVE scanning

Match visible software signals against known vulnerability data.

Directory discovery

Check common public paths for admin panels, backups, and stray files.

More on the roadmap

AWS posture, code security, and additional active checks are coming.

Pro preview

Deeper scans + watching
JS secret check

Credential pattern in a public bundle

Sensitive value in client-side code

Found in a public JavaScript bundle

Pro surfaces secrets shipped to the browser. Claim to see exact locations.

Alert

New exposed service on next scan

A service appeared that was not there last week. RedScore flagged it on the scheduled run.

Trend

Score recovered after the exposed service was closed.

Ray guidance

Known CVE matched to a visible software signal.

Upgrade the affected component.

Retest after deploy to confirm the finding clears.

Pro adds step-by-step fix notes per finding.

Claim your domain for full findings. Pro unlocks deeper modules and keeps watching.

Keep watching on your schedule

Set weekly or monthly scans, pause a domain, and pick which modules run. Email alerts on every run.

Ray tells you what to fix next

Site-specific fix notes on each finding after scans complete. Priority and sequencing that fit your stack.

See if fixes actually held

Track score and finding changes over time so you know whether a change worked or something regressed.

Pricing

Pick your depth

Free scan

$0No signup

One outside-in snapshot of any domain.

  • ·0-100 RedScore and letter grades
  • ·10 security area breakdown
  • ·Plain-English AI summary
Scan a domain

Claimed

$0Free account

Turn a one-off scan into ongoing visibility for domains you own.

  • ·Full finding details on claimed domains
  • ·Scheduled scans every two weeks
  • ·Email alert on each scan

RedScore Pro

$150/mo · or $1,500/yr

Deeper scans plus watching, guided fixes, and proof for customers and stakeholders.

  • ·Exposed services, JS secrets, and CVE checks
  • ·Ray fix guidance, trends, and custom cadence
  • ·PDF reports, trust pages, Slack and webhooks

The difference

Enterprise posture tools vs RedScore

SecurityScorecard and Bitsight are built for enterprise procurement. RedScore gives teams the same outside-in view without a sales cycle.

Outside-in domain scan

Enterprise
Often paid add-on
RedScore
Included free

Letter grades + 0-100 score

Enterprise
Vendor-specific
RedScore
Included free

Category breakdown

Enterprise
Tiered by contract
RedScore
10 areas per scan

Plain-English summary

Enterprise
Analyst reports
RedScore
Built into results

Signup to try

Enterprise
Sales cycle
RedScore
Not required

Enterprise tools: $25k+/yr

RedScore: Free

Enterprise pricing varies by contract. See full comparison

Go further with Pro

From deeper findings to fixes your team can ship

01

Ray guidance

Get finding-specific fix notes and next steps after each scan completes.

02

Reports and trust pages

Create PDF reports for stakeholders and publish a curated trust page for customers.

03

Alerts and integrations

Send scan updates to Slack, Discord, webhooks, and email so fixes reach the right team.

FAQ

Common questions

Someone will run this scan on your domain. Better if it's you.

Free scan · No signup · ~60 seconds