Is your domain secure?
Run a free, instant security scan covering SSL/TLS configuration, HTTP security headers, exposed sensitive files, cookie security, email spoofing protection (SPF/DMARC/DKIM), IP blacklist status, and WordPress/Shopify vulnerabilities — no signup required.
Not ready to scan your own site? View a sample report
SSL & TLS encryption
We verify your certificate is valid and check how many days remain before it expires, plus the TLS protocol and cipher your server actually negotiates — catching deprecated, downgrade-able configurations a valid certificate alone won't tell you about.
Learn more →
HTTP security headers
We check for CSP, HSTS, X-Frame-Options and other headers that protect against XSS, clickjacking, and data injection — with plain-language fixes for anything missing.
Learn more →
Email spoofing protection
We check your SPF, DMARC, and DKIM records to ensure scammers can't send email that looks like it came from your company.
Learn more →
IP blacklist monitoring
Aion Security checks major DNS blacklists to ensure your domain hasn't been flagged for spam or malicious activity.
Learn more →
CMS & plugin exposure
We detect WordPress, WooCommerce, and Shopify, flag exposed admin logins or an open XML-RPC API, and check installed plugins against the latest published version.
Learn more →
Continuous monitoring & alerts
Don't just scan once. Create an account to monitor your domains on the schedule you choose (daily, weekly, or monthly), compare any two past scans, get emailed the moment something regresses, and receive an automatic PDF report every month.
Exposed files & cookie security
We probe for accidentally public files like .env and .git, and check whether your cookies use the Secure, HttpOnly, and SameSite flags that keep sessions from leaking or being hijacked.
Learn more →
Advanced DNS hardening
We also check for a security.txt disclosure file, a CAA record restricting which Certificate Authorities can issue for your domain, and DNSSEC — informational signals that go beyond the baseline.
Check your dependencies for known vulnerabilities
Beyond domain security, Aion Security also scans your npm/Yarn (package-lock.json or yarn.lock), Python (requirements.txt), or PHP (composer.lock) dependencies against OSV.dev's public vulnerability database — catching known CVEs in the libraries your app actually runs, not just staleness. Free, no signup, and nothing you upload is stored or logged.