Skip to content
Turnkey Security

How it works

A plain-language explanation of what we check, how we check it, and why some results are only shown after you verify.

What we check

How we check

Everything we look at is public: DNS records anyone can look up, the certificate any browser receives, and the headers your home page sends to every visitor. We make a handful of ordinary requests, the same as a visitor opening your home page. We never try passwords, never test for break-ins, and never submit forms.

Our requests identify themselves with the User-Agent TurnkeySecurityCheck. SeeResponsible use for limits and how to opt out.

Who can see the results

Anyone can start a check of any domain, so we're careful about what we show:

Fix it yourself, then confirm

Every finding says whether you can reasonably fix it yourself, explains why it matters, and gives instructions for common setups. After you make a change, run the check again: we compare it with the last one and show what's fixed. If something can't be re-checked (for example your site didn't respond), we say so rather than calling it fixed.

What this isn't

This is an outside-in check of what's publicly visible. It isn't a penetration test, it doesn't look inside your network or devices, and passing it doesn't mean you're certified or fully secure.