Site audit
See what your business looks like from the outside: your public email authentication, what your site tells browsers, and who else is running code on your pages. Free, no account. Most checks finish in a few seconds.
Site auditPublic checks only
Common questions
- What does the audit actually look at?
- Your public DNS and your homepage, the same things any visitor or any attacker can see without permission. Email authentication, how your site is served, what it sends to browsers, and which outside companies run code on your pages.
- Why does email authentication come first?
- Because it is the one that ends with money moving. Without a DMARC record, someone can email your customer an invoice that appears to come from your domain and change the bank details on it. For anyone who quotes, invoices, or takes deposits, that is the most expensive gap on the list.
- Can I see every finding?
- The first five findings appear in priority order. Expand the remaining findings to see every observation from this free scan, or download them all. A paid audit adds investigation and checks that cannot be completed from outside.
- Does this touch or change my site?
- It makes ordinary public requests for your homepage, robots.txt, llms.txt, and sitemap.xml, and reads DNS. It follows redirects but does not submit forms, sign in, or change your site.
- My site is built with JavaScript. Will it work?
- Partly. We read the HTML your server sends, and we do not run JavaScript, so on a site that renders entirely in the browser the content and structure checks see very little. The audit tells you when that happens rather than reporting a falsely clean result.