Find out what your attacker sees first
A free grade of your public surface — TLS, HTTP headers, cookies, DNS, content and infrastructure — with the standard behind every failure and the fix next to it. No tenant, no consent, no onboarding.
The one you can start with today
Every other assessment on this site needs an administrator to consent to something. This one does not. WebScan reads what any anonymous visitor can read, so there is nothing to install, nothing to approve, and no reason to involve anyone before you know whether there is a problem.
Send a URL. You get the grade back, usually the same working day.
What you get back
- A grade, and the four counts behind it — passed, failed, not assessed and not applicable, kept apart so a low score can be read rather than argued with.
- Every failure with the standard it breaks. Not "the scanner says so" but the RFC number, which is what turns a finding into a change request somebody approves.
- Why it matters, then the fix, on each one — in the words you would use to justify the work to whoever has to schedule it.
- The hosts you did not send us. Discovery looks for the subdomains and assets attached to the name you gave, which is usually where the surprise is.
- What could not be assessed, said out loud. A check we could not run is never quietly counted as a pass.
And it stays free
This is not a sample of a paid product. WebScan's free tier runs the complete check set and shows every result — one URL at a time, for as long as you keep the tenant and with no expiry date on it. Nothing is held back from the check set. What it does not do is remember, and remembering is the whole of the paid product.
What the free tier does not do is remember. Nothing is written down when the scan finishes — so there is no history, no trend, no schedule, no alert when a passing check regresses, and no evidence to hand an auditor. That is the whole of what the licence buys, and it is also why the free tier can be free: a free scan is a short-lived function with no storage behind it.
What this is not
Not a penetration test. It grades configuration against published standards; as it stands it does not attempt exploitation and cannot see anything behind a login. It requests pages and reads DNS the way any visitor does — no fuzzing, no load, and it never writes anywhere. Active testing and authenticated scanning are on the WebScan roadmap; the free scan will stay unauthenticated and non-intrusive either way, so it is always safe to point at anything you own.
Scan my site
Send a URL. No tenant, no consent, no call first.
If your mail client did not open
Some browsers and webmail setups cannot hand off to a mail app. Nothing is lost — copy the message below and send it to jeff@jeffops.com.
Request sent
It landed. You will get a reply from a person, usually the same working day.