How it works
A plain-language explanation of what we check, how we check it, and why some results are only shown after you verify.
What we check
- Email protection. Whether your domain publishes SPF and DMARC records that stop criminals sending email that appears to come from you, and whether they're set up correctly.
- Your website's security certificate. Whether it's valid, trusted by browsers, covers your address, and isn't about to expire; and whether outdated encryption (TLS 1.0/1.1) is still switched on.
- HTTPS and browser protections. Whether visitors are always sent to the secure version of your site, and whether your site tells browsers to protect it (HSTS, frame protection, secure cookies).
- DNS basics. Whether your domain resolves correctly, and whether it reveals internal network addresses.
How we check
Everything we look at is public: DNS records anyone can look up, the certificate any browser receives, and the headers your home page sends to every visitor. We make a handful of ordinary requests, the same as a visitor opening your home page. We never try passwords, never test for break-ins, and never submit forms.
Our requests identify themselves with the User-Agent TurnkeySecurityCheck. SeeResponsible use for limits and how to opt out.
Who can see the results
Anyone can start a check of any domain, so we're careful about what we show:
- Anyone sees a short summary: what kinds of issues were found, without specifics.
- Someone with an email address at the business sees the details and the step-by-step fixes.
- Someone who proves they manage the domain (by adding a DNS record) also sees the most sensitive details, like software versions and the technical evidence.
Fix it yourself, then confirm
Every finding says whether you can reasonably fix it yourself, explains why it matters, and gives instructions for common setups. After you make a change, run the check again: we compare it with the last one and show what's fixed. If something can't be re-checked (for example your site didn't respond), we say so rather than calling it fixed.
What this isn't
This is an outside-in check of what's publicly visible. It isn't a penetration test, it doesn't look inside your network or devices, and passing it doesn't mean you're certified or fully secure.