What does your domain show the public internet?
Enter your company domain for a free, passive snapshot of your external security surface. Every issue is scored by severity and fix effort, in plain language, with the fix, the same way we score findings in a full Secvura report.
We hold ourselves to this: see secvura.com’s own snapshotWhat the check looks at
Everything here is observable by anyone on the internet. We only read; we never log in, never scan inside your application, and never store your results.
Transport security
HTTPS enforcement, HSTS, and TLS certificate health.
Application headers
CSP, clickjacking protection, nosniff, referrer policy.
Session cookies
Whether session and auth cookies carry HttpOnly, Secure and SameSite.
Email security
SPF, DKIM, DMARC and MTA-STS: can attackers send email as you, or intercept mail to you?
DNS hygiene
CAA records and a signposted way to report vulnerabilities.
Information disclosure
Stack and version numbers leaking in your headers.
What it can’t see, and why that matters
This is the outside view. The findings that most often cost companies real money live inside the application: broken access control, an ID you can change in a URL to read another customer’s data, injection, and authentication flaws. An automated external check can’t reach those. Finding them is what a hands-on Secvura security review is for.
Surface Check FAQs
Is the Surface Check free?
Yes, completely free. There's no sign-up, no account, and no card required. Enter your domain and you get the result straight away.
Is it safe to run on my website?
Yes. The check is passive and read-only. It only reads what your domain already shows the public internet: HTTP response headers, the TLS certificate, and public DNS records. It never logs in, never scans inside your application, and sends nothing intrusive.
Do you store my domain or the results?
No. The snapshot is generated live each time and is not stored. If you share the result link, opening it simply re-runs the same passive check.
What does the check look at?
HTTPS enforcement and HSTS, TLS certificate health, security headers (CSP, clickjacking protection, nosniff, referrer policy), session-cookie flags, email security (SPF, DKIM, DMARC and MTA-STS), DNS hygiene (CAA and security.txt), and whether your software and version leak in your HTTP headers. Every issue is scored by severity and by how much effort it takes to fix.
Is this the same as a full security review?
No. This is the outside view only. The issues that most often cost companies money live inside the application (broken access control, an ID you can change in a URL to read another customer's data, injection, and authentication flaws), which an automated external check can't reach. A full Secvura security review is a hands-on assessment that finds those, at a fixed price of £1,200 with a report in one to two weeks.
How accurate is it, and can I act on it?
Every finding reflects something we actually observed on your domain, with a plain-language explanation and a concrete fix your team can follow. It's a genuine, if narrow, starting point. Where a check can't be conclusive from the outside, such as DKIM, which depends on a selector we can't always guess, we say so rather than raise a false alarm.