What the platform checks

Every check below is built and running today. They all land in the same dashboard.

The ClickScan dashboard: asset grades, open findings and what changed since the last scan The ClickScan dashboard: asset grades, open findings and what changed since the last scan
Click the image to see it full size.

Website encryption (SSL/TLS)

Certificate expiry and trust chain, every protocol and cipher your server accepts, and named weaknesses probed actively rather than guessed.

Browser security headers

HSTS, CSP, X-Frame-Options and the rest — graded on how strict they are, not merely whether they exist. Point it at a custom port if your app is not on 443.

Email authentication (SPF, DKIM, DMARC)

What stops somebody sending email as you. MX, SPF, DKIM, DMARC, MTA-STS, TLS-RPT and BIMI, with the raw DNS answers in the report and the exact records to publish.

Live spoofing test

Delivers one forged message to an address at the domain under test and reports whether it was accepted. Proof rather than inference. Needs the domain proven yours.

Domain and DNS security

Whether the answers DNS gives about your domain can be trusted not to have been forged. DNSSEC in four states — not signed, signed but never anchored at the registrar, broken, or working — and each state comes with the one thing to change.

It also reads which certificate authorities you allow to issue for the domain, and compares that against the ones that actually have. A certificate taken out in your name by an authority you never authorised is one of the earliest signs somebody is preparing to impersonate you.

Brand Impersonation Monitor

Brand protection: thousands of variations of your name, resolved against DNS, mail servers and certificate logs, with a verdict on what each domain found can actually do.

Brand impersonation — deep sweep

The same check, much wider: every country ending rather than the common ones, two look-alike substitutions at once, every single-character typo.

Breach exposure check

Which known breaches an address appears in and what types of data each held. The breached values never reach us. Needs the address proven yours.

Port Scan

Which ports on a host are reachable from the internet and what is answering on them. An active check, so it needs the asset proven yours first.

Both tiers also report what a public internet-wide index already publishes about the same addresses — what somebody learns about you before touching anything of yours.

Port Scan — full range

All 65,535 ports rather than the ones services are traditionally assigned to, and each open port is asked what it is running instead of being read off its number.

Subdomain discovery

The other names attached to your domain — the staging site, the old gateway, the thing a contractor left running — and the ones pointing at a cloud service you stopped paying for, which anybody can claim.

It also works out whether the domain is served through a filtering service — the kind that sits in front of a website to absorb attacks — and names the hosts that answer on their own address, around it. That is a way in that skips the protection you are paying for.

Subdomain discovery — deep sweep

A far wider list of names, one level deeper than your domain, and it reads each host’s icon to identify the software — turning “this name suggests Jenkins” into “this host is running Jenkins”.

It has a further way of recognising the filtering service in front of a host, so it can answer where the standard sweep can only say it cannot tell.

DNS record generator

Builds the exact records that fix an email report — SPF, DKIM, DMARC, MTA-STS, TLS-RPT and BIMI — ready to paste into your DNS. Runs in the browser and costs nothing.

More checks are on the way

A check appears here the moment it runs, not when it is planned — so this list is always what the platform can do today. If you need something that is not on it, ask us.

How we decide what counts

Two rules underneath every check on this page. They are the reason a grade from us is worth quoting to somebody else.

Somebody else’s data never sets your grade

Part of what a report shows was observed by a third party rather than by us — what a public internet-wide index already publishes about your addresses, for instance. It belongs in the report, because it is exactly what an attacker learns for free before touching anything of yours.

So we show it, and we keep it out of your grade. The grade reflects only what we tested ourselves, and these observations are counted on their own rather than folded into your finding count. A number we are accountable for should not be movable by somebody else’s data.

Every list we look things up in has a date on it

A check is only as good as the reference data behind it. So every list we did not write ourselves carries where it came from, when it was last refreshed and how far we trust it — and that limit is applied where the grade is worked out, not painted on at the end, so an exported report carries it too. Data we have not verified ourselves can add coverage; it is not allowed to raise the alarm on its own, and a report says when a finding was held back for that reason rather than leaving you to wonder why we disagree with another tool.

Where a list is too old to rely on, the check says nothing instead of guessing. Telling you there is a hole in your defences because our own copy of somebody’s published data went stale is the worst way for us to be wrong, so we would rather tell you nothing than tell you something we cannot stand behind.