Meet CyberTrust Score, a free external scan that grades any domain’s public security posture, from DNS to email authentication, TLS, and HTTP headers. No agent, no account, no card. Just the score your buyers and attackers already see.
Enter a domain, get a letter-grade score and a ranked list of exactly what to fix.
Basic scans are free and require no account. Sign in only if you want saved history.
We read only publicly observable signals, the same surface an attacker maps first.
Show your score on your own site to prove posture to customers and prospects.
Your prospects’ security teams are already scanning you. So are attackers. CyberTrust Score just lets you see the result first, and fix it before it costs you a deal.
Prospects, partners, and security teams can read your public posture, DNS, email authentication, TLS, headers, exposure, long before a sales call. If it looks weak, the deal stalls.
Anyone can read your DNS, email authentication, and TLS setup from the outside, including the buyer’s security team.
A missing DMARC policy or an expired certificate quietly signals risk and slows the security review.
Without a clear, outside-in view, the easy wins that lift trust stay invisible.
Every grade is built from the public signals that decide whether your domain looks trustworthy, or exposed.
Records, nameservers, and configuration hygiene that everything else is built on.
SPF, DKIM, and DMARC, the controls that stop attackers spoofing your domain.
Certificate validity, protocol versions, and cipher strength on your public endpoints.
HSTS, CSP, and the headers that harden every page you serve to the world.
Publicly visible misconfigurations and signals that invite a closer look.
Every scan returns a letter grade, a 0-100 score, and a ranked list of exactly what to fix first.
One free score, useful at every step.
Before you buy anything, see where you stand. No commitment, no agent, no card.
Score the partners and suppliers you depend on, in seconds, from the outside.
Walk into the buyer’s security review already knowing what they’ll find.
Re-scan anytime you ship. Show movement and momentum, not a stale snapshot.
No agent, no access, no guesswork, just the public signals your buyers and attackers already see, scored the same way every time.
Free, external, and honest about what the world already sees. Then fix what matters, with a US-based team, if you want the help.