Free Tools
Free, passive security checks at launchsafe.com/tools: DNS, email security, headers, certificates, security.txt, packages, JWTs and secrets.
The free tools at launchsafe.com/tools need no account. They are passive: they read DNS, public logs and databases, or make one request to the address you enter. Private and internal addresses are refused. What you enter is not logged or kept. Your IP address is used only to count requests for rate limiting.
| Tool | What it does |
|---|---|
| DNS lookup | A, AAAA, CNAME, MX, TXT, NS, CAA and SOA records, as 1.1.1.1 resolves them |
| Email security check | SPF, DMARC, DKIM, MTA-STS, TLS-RPT and BIMI, with records to add |
| Security headers check | CSP, HSTS, framing and more, graded, with fixes to copy |
| SSL certificate check | Issuer, names and expiry from Certificate Transparency, and HSTS preload status |
| security.txt checker | Validates a security.txt against RFC 9116, or generates one |
| Package vulnerability lookup | Known advisories for an npm or PyPI version |
| JWT decoder | Header, claims and expiry, with weak settings flagged. Runs in your browser |
| Secret checker | Finds strings that look like API keys. Runs in your browser |
Each tool's page says what it checks and, as plainly, what it does not.
These tools are not a LaunchSafe scan. For findings in your code, see the introduction.