Anvil checks what attackers see from the outside — email spoofing, TLS, security headers, exposed subdomains — and hands you a branded report a client can actually read. Passive by design: public data only.
Every check reads public information only — no authentication, no exploitation, no intrusive scanning. Safe to run against any public domain.
SPF, DKIM, and DMARC. The finding owners react to fastest: "anyone can email as your company."
Expiry, validation, and deprecated TLS 1.0/1.1 still left enabled.
HTTPS upgrade, HSTS, CSP, clickjacking, MIME-sniffing, and cookie flags.
Hosts discoverable in public certificate transparency logs — the forgotten staging box.
Software versions leaked in response headers that map straight to known CVEs.
DNSSEC and mail-exchanger configuration.
Anvil is the door-opener. The money is in the fix.
Enter a prospect's domain above. One click, under a minute, entirely on public data.
Hand over a branded, graded report with plain-English fixes. It looks like it cost money.
Remediation, a retainer, or monthly monitoring. The report is how the conversation starts.
Scan here for free anytime. Own the tool for unlimited scans, order a done-for-you report, or keep an eye on your posture with weekly monitoring.
Download and run unlimited scans, for as many clients as you want. Yours forever.
Send us a domain you're authorized to assess. Get a fully branded report and a 20-minute findings call in 2 business days.
We re-scan your domain every week and email you the moment your security grade drops or a new issue appears.
Yes. The scan is passive — it reads public data the same way a browser or mail server does, and performs no exploitation or intrusive testing. Anything beyond passive assessment requires written authorization for the specific systems first.
To scan here: nothing — type a domain. To run the downloadable tool: basic comfort with a command line and Python. The report itself is written for non-technical readers.
Yes — the downloadable tool lets you set your company name, contact line, and accent color on every report.
No. It reflects the externally observable posture at scan time and is a starting point, not a guarantee. Findings should be validated before remediation.