Domain Risk HeatMap

Get a clear picture of risks, impact and recommended actions.

Free and no sign-up required — results in 30s

Free

A visual audit of the domain’s public infrastructure, showing how the website, DNS, email, CDN, WAF, server, CMS and related technologies are connected — and where risk indicators are detected.

Domain Dependency & Risk Map analyses the public technical footprint of a domain and organises the findings into an interactive infrastructure map.

This allows business and technical teams to quickly answer questions such as:

  • Is the domain properly configured and active?
  • Are DNS and email services correctly exposed?
  • Is there evidence of CDN or WAF protection?
  • Where are the strongest risk signals located?
  • Are there missing, weak or unclear layers in the domain setup?
What is analysed

9 analyses included


Security

TLS Connection & Certificate

Checks that the site serves HTTPS with a valid, in-date certificate, detects support for outdated TLS versions and verifies the redirect from HTTP to HTTPS

Security Headers

Analyzes a website's HTTP security headers, verifies their presence and validates that the values are secure and correctly configured, and passively detects whether a WAF or anti-bot protection is in place

Information Exposure

Detects sensitive information leaks such as software versions in headers, accessible configuration files, backups and directory listings


Performance

Essential Performance

Measures key speed indicators of the main page: server response time (TTFB), page weight, compression, HTTP protocol version and cache headers

Asset Optimization

Checks CDN usage for static assets, modern image formats and preconnect/dns-prefetch configuration for external web font providers


Reputation

Essential SEO & Metadata

Checks essential HTML metadata for SEO and social sharing (title, meta description, favicon, canonical, meta robots, H1, lang, viewport, Open Graph, structured data) and validates the existence and correctness of robots.txt and sitemap.xml

Essential Accessibility

Checks essential web accessibility criteria (WCAG) on the public HTML: alternative text on images, semantic landmarks, links/buttons without accessible text, and declared language

DNS & Email Reputation

Checks the domain's SPF, DKIM and DMARC records to detect the risk of email spoofing, verifies whether its IP appears on spam blacklists (DNSBL) and confirms whether the domain has DNSSEC correctly configured (not just whether it publishes a DS)

Compliance & Trust

Checks for the presence of legal links (privacy, cookies, legal notice), a cookie consent banner, tracking scripts and mixed content

Out of scope

What this audit does not cover


All checks are performed remotely against publicly reachable endpoints, without authentication and without any destructive or exploitative action.

This audit does not include:

  • Active exploitation or penetration testing against the target
  • Authenticated or credentialed testing, including logins, admin panels, private areas, or internal systems
  • Source code review or static application security testing
    Load testing, denial-of-service simulation, stress testing, or destructive checks
  • Manual legal review or formal compliance certification
    Full SEO audit, content audit, or backlink analysis
  • Malware removal, incident response, or forensic investigation
  • Infrastructure review beyond externally observable indicators
  • Guaranteed detection of all vulnerabilities, misconfigurations, outages, or compliance issues