Free Tools

Free, passive security checks at launchsafe.com/tools: DNS, email security, headers, certificates, security.txt, packages, JWTs and secrets.

Edit on GitHub

The free tools at launchsafe.com/tools need no account. They are passive: they read DNS, public logs and databases, or make one request to the address you enter. Private and internal addresses are refused. What you enter is not logged or kept. Your IP address is used only to count requests for rate limiting.

ToolWhat it does
DNS lookupA, AAAA, CNAME, MX, TXT, NS, CAA and SOA records, as 1.1.1.1 resolves them
Email security checkSPF, DMARC, DKIM, MTA-STS, TLS-RPT and BIMI, with records to add
Security headers checkCSP, HSTS, framing and more, graded, with fixes to copy
SSL certificate checkIssuer, names and expiry from Certificate Transparency, and HSTS preload status
security.txt checkerValidates a security.txt against RFC 9116, or generates one
Package vulnerability lookupKnown advisories for an npm or PyPI version
JWT decoderHeader, claims and expiry, with weak settings flagged. Runs in your browser
Secret checkerFinds strings that look like API keys. Runs in your browser

Each tool's page says what it checks and, as plainly, what it does not.

These tools are not a LaunchSafe scan. For findings in your code, see the introduction.