Skip to main content

Free tools

Small checks that answer one question properly

Each of these does one thing and explains the result honestly, including what it cannot tell you. They are genuinely free, require no account, and are not a funnel dressed up as a utility.

All tools perform passive public checks only. Nothing here probes, authenticates or tests infrastructure.

Where the line is

What these tools deliberately do not do

Every check here reads something a website already publishes to anybody who asks for it: a file at a known address, a DNS record, a response header, the markup of a page. That is the whole boundary. No tool on this site authenticates, enumerates, probes for weaknesses or sends anything a normal browser would not send.

This is a deliberate limit rather than a technical one. A tool that scanned any domain typed into it would be trivial to build and irresponsible to publish, because the person typing the domain is very often not the person who owns it. Active technical assessment happens only under a separate signed authorisation with a defined scope, an agreed window and a named authorising individual.

The second limit is about honesty. A check that cannot establish something says so, rather than reporting an absence as a fault. DKIM selectors are not publicly enumerable; a missing common selector proves nothing. A blocklist lookup that times out is a failed lookup, not a clean result. Reporting uncertainty as certainty is the fastest way to make a free tool useless.

Interpretation

A passed check is not the same as a good website

These tools measure configuration. Configuration is necessary and rarely sufficient.

Everything green, no enquiries

Entirely possible. A technically immaculate site that never states plainly what the business does, or that competes for terms nobody with money searches for, will pass every check here and still fail commercially.

Several warnings, performing well

Also common, and not a contradiction. A site with strong content and genuine authority tolerates a good deal of technical imperfection. The warnings are worth fixing; they are rarely the reason for anything.

What actually decides it

Whether the site covers what buyers search for, answers those questions better than the alternatives, and makes acting on it obvious. That judgement is what an assessment is for, and it is not something a check can perform.

Questions about the tools

Do I need an account to use these?
No. There is no sign-up, no email wall on the tool itself, and no limit beyond a rate limit that exists to stop the endpoints being used as a scanning service. You can run any of them and leave without giving us anything.
What happens to the addresses I enter?
The tools do not write to storage. A request is made, a result is returned, and nothing about it is retained afterwards. The rate limit works from a salted, truncated hash of the requesting address which cannot be reversed to identify anyone, and which expires within the hour. The Website Intelligence Checker is the exception: because it produces a shareable result page, that snapshot is retained for a limited period, which is set out in our data retention policy.
Are these the same checks used in a paid audit?
Some of them are, but they are a small part of it. The tools establish facts about public configuration. An audit uses those facts as a starting point and adds the part a tool cannot do: deciding which of them matters for your business, in what order, and what should be done about it.
Why is there no vulnerability scanner?
Because running one against a website you may not own would be irresponsible, and in most jurisdictions unlawful. Everything here reads information a website already publishes to anyone who asks. Active testing of infrastructure requires a separate signed authorisation with a defined scope, and is never triggered from a public form.
A tool says something is missing, but our developer disagrees.
That happens, and it is usually informative rather than a contradiction. These checks see what a public, unauthenticated request sees. A configuration that is applied only to logged-in traffic, only to recognised search-engine user agents, or only at a CDN edge in another region will produce a different result. Where a check cannot establish something, it says so rather than assuming the worst.

A check answers one question. An assessment answers the one you actually have.

If a tool has told you something is missing and you want to know whether it matters, run the full snapshot or start a conversation.

Scores are directional assessments based on the available evidence and should not be interpreted as search-engine rankings.