One combined scan covering SSL certificate validity, HTTP security headers, and SPF/DKIM email authentication — with an overall score and prioritized fixes.
✍️ Author: ToolsNovaHub•📅 Last Updated: 12 September 2026•🔧 Methodology: SSL via Certificate Transparency logs, SPF/DKIM via public DNS, headers via server-side proxy (10s timeout, private/internal IPs blocked)
Examples:
github.comcloudflare.com
🔄 Scanning SSL, headers & email authentication…
🏆 Overall Security Score
—
—
🔒 SSL Certificate
—
🛡️ Security Headers
—
📧 Email Authentication
—
💡 Prioritized Recommendations
ℹ️ The Security Headers portion of this scan requires the same one-time Cloudflare Worker setup as Security Headers Checker — SSL and email authentication checks work immediately without it.
📚 What This Scanner Checks
Website Security Scanner combines three independent checks — each also available as a standalone tool — into a single pass so you get the full picture without running three separate lookups:
Category
What's Checked
Standalone Tool
SSL/TLS
Certificate validity, days remaining, issuer, from Certificate Transparency logs
Each of the three categories contributes roughly a third of the overall score. Within SSL, an expired or soon-expiring certificate weighs heaviest. Within headers, HSTS and CSP carry the most weight since they block the highest-impact attack classes. Within email authentication, having neither SPF nor DKIM configured at all is treated as the most significant gap, since it leaves the domain fully spoofable.
⚠️ What a Combined Scan Doesn't Replace
This is a breadth-first overview, not a substitute for a full penetration test, live TLS/cipher-suite audit, or DMARC policy review. For deeper analysis of any single category, use the dedicated standalone tool linked in the table above, or read our full 20-point Website Security Checklist.
🔒 Authorized Use Only
This scanner reads only publicly available information — SSL certificate data, published security headers, and public email authentication (SPF/DKIM/DMARC) records — the same data any visitor's browser or mail server already receives. It does not attempt to bypass access controls, exploit vulnerabilities, or access non-public systems. You should only run this scan against domains you own or have explicit permission to assess; running any assessment against third-party infrastructure without authorization may violate that organization's terms of service or applicable law, regardless of the tool used.
🔧 Troubleshooting
⚠️ Scan times out or returns partial results
Some servers rate-limit or block automated requests, including from scanning tools like this one — a timeout doesn't necessarily mean the site is broken, just that this particular check couldn't complete.
⚠️ Score dropped after no visible site changes
A certificate nearing expiry, a header that silently reverted after a CDN config change, or a newly disclosed issue in a library the site uses can all lower a score without any change on your end — re-run individual checks (SSL Checker, Security Headers Checker) to isolate which factor moved.
⚠️ Flagged as insecure despite HTTPS working
This scanner checks more than whether HTTPS loads — mixed content, weak headers, or an incomplete certificate chain can all lower the score even on a site that appears to load securely in a browser.
🛠️ Use Cases
🚀
Pre-Launch Sanity Check
Run one scan before shipping a new site to catch the most common, highest-impact gaps in under a minute.
🔄
Post-Migration Verification
After a hosting, CDN, or DNS provider migration, quickly confirm nothing important silently broke.
📊
Vendor / Third-Party Due Diligence
Get a quick baseline read on a vendor or partner's public-facing security posture before deeper engagement.
📈
Tracking Improvement Over Time
Re-scan periodically to confirm security posture is trending in the right direction as fixes get deployed.
ToolsNovaHub tools are built and independently maintained with a focus on accurate, no-signup network and security utilities. Spotted an error? Let us know.
🎓
Expert Tip
A single scan from Website Security Scanner is a snapshot — security posture drifts as certificates near expiry or headers get overwritten by a new deploy, so schedule periodic re-checks.
⚠️
Common Beginner Mistake
Assuming a perfect score from Website Security Scanner means the site is fully secure. It checks configuration, not application-layer bugs like SQL injection — pair it with a manual code review.
SSL/TLS certificate validity via Certificate Transparency logs, HTTP security headers, and SPF/DKIM email authentication presence — all in one combined scan.
Is this the same as Security Headers Checker? +
No — Security Headers Checker focuses solely on headers with a detailed breakdown. This scanner combines that with SSL and email authentication for a broader, less granular overview.
What is a good overall security score? +
85+ generally reflects solid configuration across all three categories. Below 60 usually points to at least one major gap.
Does a low score mean my site is actively being attacked? +
No — it reflects missing defensive configuration, not an active compromise. It highlights preventable gaps, not evidence of an ongoing incident.
Can I scan a domain I don't own? +
Yes. Certificate Transparency logs, public HTTP headers, and public DNS records are all publicly accessible information by design.
Is this scan free? +
Yes — free, no sign-up required. The scan runs against live public data (headers, certificates, DNS) each time, so results reflect the current state at the moment you run it.
Does this replace a full penetration test? +
No — it's a breadth-first automated overview of public-facing configuration, not a substitute for manual security testing or a live TLS/cipher audit.
Why does the scan check email authentication for a website tool? +
A domain's email configuration is part of its overall security posture — a website can have a perfect SSL/headers setup while remaining fully spoofable for phishing via email if SPF/DKIM are unset.
Can I get a detailed breakdown instead of just a score? +
Yes — each of the three category cards shows specifics, and you can always drill into the dedicated standalone tool (SSL Checker, Security Headers Checker, SPF/DKIM Lookup) for full depth.
How often should I re-run this scan? +
After any hosting, DNS, or CDN change, and periodically otherwise (quarterly is reasonable for most sites) to catch silent regressions.
Does a missing DKIM selector count against my score even if I use a different selector? +
The scan checks a handful of common selectors (google, selector1, k1, etc.) — if your domain uses a non-standard selector, use the dedicated DKIM Lookup tool with your exact selector for an accurate check.
Can I download or share the scan results? +
Yes — use the Print / Save as PDF button, or copy the raw JSON for your own records or ticketing system.
Why is my score different from Security Headers Checker's grade? +
This scanner's score blends three categories together, so a strong headers grade can still be pulled down by a weak SSL or email authentication result, and vice versa.
Does this tool check DMARC too? +
Not in the current version — it checks SPF and DKIM presence. For full DMARC policy analysis, this is planned for a future update; in the meantime check your DMARC TXT record manually via DNS Lookup.
Can I use this to compare two domains side by side? +
Not automatically within one view — run the scan on each domain separately and compare the score cards, or export both as JSON for your own comparison.