Free Threat Intel Toolkit

Fourteen free security lookups — DNS, TLS, headers, threat intelligence and more — no sign-up required, results in seconds.

No login · 30 calls / hour / IP · EU data residency

DNS Lookup Query all standard DNS records (A, AAAA, MX, CNAME, TXT, NS, CAA, SOA) for any domain name. Reverse DNS Find the associated domain name (PTR record) for any public IPv4 or IPv6 address. Blacklist Check if your public IP address or mail server is blacklisted on major spam reputation blocklists. Propagation Verify DNS record updates and query propagation status across multiple global DNS resolvers. Security Headers Analyze and grade the security header posture of any website — HSTS, CSP, CORS and more. TLS Inspector Inspect public Certificate Transparency logs for any issued SSL/TLS certificate, expiry and SANs. Tech Stack Detect the web servers, CDNs, frameworks, CMS, and analytics scripts powering any public website. Email Auth Audit DMARC, SPF, and DKIM configuration records to prevent attackers spoofing your domain. DNSSEC Verify the cryptographic DNSSEC validation chain (DS and DNSKEY records) for your domain name. WHOIS / RDAP Query domain registration details, registrar, status codes, and creation/expiry dates via RDAP. Cookie Audit Detect session identifiers and tracker cookies missing Secure, HttpOnly, and SameSite attributes. HSTS Preload Check if your domain is hardcoded into major browser HSTS preload lists, forcing HTTPS from the first visit. Threat Intel Aggregate Shodan, URLhaus, ThreatFox and IP reputation to check if a domain, IP, or email is flagged. CryptoCheck Grade TLS version, cipher suites, HSTS preloading, cookie safety, and post-quantum readiness.
Enter a hostname to look up A, AAAA, MX, NS, TXT, CNAME, SOA, CAA records.

Free Online DNS Record Lookup Tool

Query all standard DNS records (A, AAAA, MX, CNAME, TXT, NS, CAA, SOA) for any domain name. Results are resolved directly from global authoritative name servers via secure DNS over HTTPS (DoH).

Resolve a public IP back to its PTR records (hostname).

Reverse DNS Lookup (PTR Check)

Find the associated domain name (PTR record) for any public IPv4 or IPv6 address. Helpful for verifying mail server reputation and tracing IP back-references.

Checks a public IPv4 against 4 major DNS blacklists (Spamhaus ZEN, Barracuda, SpamCop, PSBL). Useful before launching a mail server or diagnosing deliverability problems.

Spam DNSBL Blacklist Checker

Check if your public IP address or mail server is blacklisted on major spam reputation blocklists (Spamhaus, Barracuda, SpamCop). Critical for email deliverability diagnostics.

Score the target's HTTP security headers — HSTS, CSP, COOP, CORP, X-Content-Type, frame-ancestors, etc. Letter grade A+ to F.

HTTP Security Headers Grader

Analyze and grade the security header posture of any website. Instantly test HSTS, Content Security Policy (CSP), CORS, X-Frame-Options, and cookie configurations.

Pulls every issued certificate from public Certificate Transparency logs (crt.sh). Shows issuer, expiry, SAN list, serial.

TLS/SSL Certificate Inspector

Inspect public Certificate Transparency (CT) logs to view all issued SSL/TLS certificates, expiry dates, Subject Alternative Names (SAN), and issuers for any domain.

Identify CDN, web server, framework, analytics, payments, CMS — based on response headers + first 100 KB of HTML.

Technology Stack Detector

Detect the underlying web servers, CDNs, frameworks, CMS, analytical scripts, and payment gateways powering any public website.

Queries 5 public DoH resolvers (Cloudflare, Google, Quad9, AdGuard, OpenDNS) in parallel. Useful when DNS changes are mid-propagation.

Global DNS Propagation Checker

Verify DNS record updates and query propagation status across multiple global DNS resolvers (Cloudflare, Google, Quad9, OpenDNS) in real-time.

Pulls SPF, DMARC, DKIM (common selectors), MTA-STS, and MX records. Flags spoofing-friendly policies before an attacker finds them.

Email Spoofing & Phishing Security Audit

Audit DMARC, SPF, and DKIM configuration records for your domain. Ensure proper alignment and prevent attackers from spoofing emails from your company.

Looks for DS and DNSKEY records and reports whether the resolver was able to authenticate the chain. Unsigned zones are vulnerable to DNS hijacking.

DNSSEC Validator & Validation Check

Verify the cryptographic DNSSEC validation chain (DS and DNSKEY records) for your domain name. Protect users from DNS hijacking and cache poisoning attacks.

RFC 7482 RDAP lookup. Returns registrar, creation / update / expiry dates, status flags, and nameservers — no HTML scraping.

WHOIS & RDAP Domain Registry Lookup

Query domain registration details, registrar name, registry status codes, creation, update, and expiration dates using the modern RDAP protocol.

Queries hstspreload.org for the domain's current status — preloaded, pending, removed, or unknown. Preloading guarantees the first request is HTTPS.

HSTS Preload List Status Check

Check if your domain is submitted and hardcoded into major browser HSTS preload lists. Force HTTPS connections from the very first visit.

Aggregates Shodan InternetDB exposure, URLhaus malware hosting reputation, ThreatFox IOCs, CIRCL CVE-search, crt.sh certificate-transparency footprint, and IP ASN/geo into one keyless lookup. Results cached 1 hour. 10 calls / minute / IP.

Aggregated Threat Intelligence Lookup

Aggregate intelligence from Shodan, URLhaus malware tracking, ThreatFox IOCs, and IP reputation to check if a domain, IP, or email is flagged in malicious activities.

Enter a hostname without https:// — e.g. assureport.com
Cryptographic hygiene, made simple. Grades TLS version, cipher suites, HSTS header, HSTS preload list, cookie flags, and post-quantum readiness — returns an A+→F score with a viral SVG badge.

CryptoCheck: TLS/HSTS Cryptographic Grader

Grade the cryptographic hygiene of TLS version, cipher suites, HSTS preloading, cookie safety flags, and post-quantum readiness (Kyber) with an embeddable badge.

Run a real penetration test on the same target.

The free toolkit answers "what's exposed?" — but what about "what is exploitable?". AssurePort's AI pentest pipeline produces proof-of-concept evidence and remediation code in your stack's language. From $69 for a Starter scan, no card required to sign in.

Sign in & try a scan →

Download AssurePort Browser Extension

Audit security headers, cookie flags, and TLS hygiene instantly on any active browser tab. Includes direct integrations and one-click target verify.

Download Extension (ZIP)
Download PDF Report
Generate a professionally branded GRC/compliance PDF report for your target. Register a free account to download and share the results.