Quick checks for the questions that shouldn't need a signup form. No email gates, no accounts - each tool links to free continuous monitoring if you want the question answered permanently instead of once.
The tools marked Agent-ready also publish themselves as WebMCP tools, so an AI agent running in your browser can call the check directly and read the JSON instead of driving the form.
Expiry countdown, chain trust, hostname match, protocol and SANs - the full picture of any certificate in seconds.
Open toolWhen a domain expires, its registrar, status codes, and nameservers - live from registry RDAP data.
Open toolCheck an address from your logs against Spamhaus DROP, IPsum, and URLhaus - with reverse DNS and a plain verdict.
Open toolGrade any site A+ to F on HSTS, CSP, and four more headers - with per-header fixes and a free JSON API for CI.
Open toolPaste your SSH log: who attacked, usernames tried, and whether anyone got in. Parsed in your browser - never uploaded.
Open toolA read-only script that grades your server on SSH, firewall, updates, kernel settings, and more. Read it before you run it.
Open toolCheck any site from outside your network: status, redirect chain, and a DNS/TCP/TLS/first-byte timing waterfall.
Open toolBuild a crontab schedule from dropdowns or paste one to decode it - plain English plus the next five run times.
Open toolPaste uname -r and see which eBPF features your kernel has - CO-RE, ring buffer, BPF LSM - and whether modern tools will run.
Open toolPick your providers and get the exact SPF, DKIM, DMARC and MX records, a lookup-budget check, a staged DMARC plan, and one-click verification.
Open toolMX, SPF with lookup count, DMARC, DKIM, MTA-STS and TLS-RPT in one graded report - plus a blacklist check of every mail server.
Open toolAny record type against Cloudflare, Google, and Quad9 at once - with TTLs and a propagation consistency verdict.
Open toolThe blog goes deeper: runbooks for compromise checks, SSH login alerting, and server hardening.