Built GuardHawk β a one-click website security audit tool. Point it at any domain you own or manage, get a full report back in seconds: no login, no agent installed, nothing invasive β just reads what's already publicly checkable (the same way a browser or a certificate authority would).
What it checks, all in one run:
β
SSL/TLS certificate (valid, expiry, issuer)
β
DNS records + DNSSEC
β
Email security β SPF, DKIM, DMARC (is your domain spoofable by phishers?)
β
Security headers (HSTS, CSP, Permissions-Policyβ¦)
β
Subdomain-takeover risk (a dangling DNS record pointing to a service you don't control anymore β a real, common way domains get hijacked)
β
Public cloud-storage exposure (accidentally public S3 buckets)
β
Tech stack, WHOIS, blacklist status
β
A 0-100 health score + a plain-English fix list
Real example β ran it just now:
I ran GuardHawk against github.com:
π github.com β 94/100 (Grade A)
β
SSL/TLS checked
β
SPF, DKIM & DMARC checked
β
Security headers checked
β
No subdomain takeover risk detected
β
No public cloud buckets detected
β
Blacklist status checked
β‘ Response time: 72 ms
It still identified 2 issues worth reviewing:
β οΈ Permissions-Policy header missing
β οΈ DNSSEC not enabled
That's exactly what GuardHawk is built for β giving you a quick view of what is configured correctly and what still needs attention. Even a site the size of GitHub has fixable gaps β nobody's perfect, you just need to actually see the list.
Where this fits:
π§ Agencies & MSPs auditing client sites before onboarding
π€ Drop it into an n8n workflow for scheduled security monitoring across a whole portfolio of domains
π Runs on Apify β one domain or bulk-audit hundreds, no API key needed
π apify.com/inexhaustible_glass/domain-health-audit
What's the last security gap you found on a "trusted" site? π
Top comments (0)