External security posture · free scan

Turn any domain into a security report in 60 seconds.

Anvil checks what attackers see from the outside — email spoofing, TLS, security headers, exposed subdomains — and hands you a branded report a client can actually read. Passive by design: public data only.

Passive · reads only public DNS, TLS, HTTP headers & certificate-transparency logs. Public hosts only.
No account · no API key · results in under a minute
Coverage

What Anvil checks

Every check reads public information only — no authentication, no exploitation, no intrusive scanning. Safe to run against any public domain.

email

Spoofing protection

SPF, DKIM, and DMARC. The finding owners react to fastest: "anyone can email as your company."

tls

Certificates & protocols

Expiry, validation, and deprecated TLS 1.0/1.1 still left enabled.

http

Security headers

HTTPS upgrade, HSTS, CSP, clickjacking, MIME-sniffing, and cookie flags.

surface

Exposed subdomains

Hosts discoverable in public certificate transparency logs — the forgotten staging box.

leaks

Version disclosure

Software versions leaked in response headers that map straight to known CVEs.

dns

DNS hygiene

DNSSEC and mail-exchanger configuration.

The workflow

Report today, paid work next

Anvil is the door-opener. The money is in the fix.

01

Scan it

Enter a prospect's domain above. One click, under a minute, entirely on public data.

02

Send the report

Hand over a branded, graded report with plain-English fixes. It looks like it cost money.

03

Sell the fix

Remediation, a retainer, or monthly monitoring. The report is how the conversation starts.

Pricing

Free to scan. Own it, hand it to us, or let us watch it.

Scan here for free anytime. Own the tool for unlimited scans, order a done-for-you report, or keep an eye on your posture with weekly monitoring.

ANVIL — THE TOOL
$39

Download and run unlimited scans, for as many clients as you want. Yours forever.

  • Unlimited branded reports
  • JSON output for scripting
  • Selling playbook included
  • Perpetual commercial license
Get Anvil
Done for you REPORT SERVICE
$250

Send us a domain you're authorized to assess. Get a fully branded report and a 20-minute findings call in 2 business days.

  • We run the full scan
  • Branded to you
  • Findings call included
  • Nothing to install
Order a report
CONTINUOUS MONITORING
$19/mo

We re-scan your domain every week and email you the moment your security grade drops or a new issue appears.

  • Automated weekly re-scan
  • Alert on any change
  • Fresh report each month
  • Cancel anytime
Start monitoring
Built by a US Army veteran and cybersecurity practitioner (CPPT).
Anvil is defensive tooling. It observes only what any visitor or mail server can already see — no exploitation, no intrusive testing. For deeper authorized engagements, get written scope first.
Questions

Good to know

Is it legal to run on any website?

Yes. The scan is passive — it reads public data the same way a browser or mail server does, and performs no exploitation or intrusive testing. Anything beyond passive assessment requires written authorization for the specific systems first.

Do I need to be technical?

To scan here: nothing — type a domain. To run the downloadable tool: basic comfort with a command line and Python. The report itself is written for non-technical readers.

Can I put my own brand on the reports?

Yes — the downloadable tool lets you set your company name, contact line, and accent color on every report.

Does it guarantee a site is secure?

No. It reflects the externally observable posture at scan time and is a starting point, not a guarantee. Findings should be validated before remediation.