Intrusive checks require an account, plus proof that you control this domain — publish a token on the host and verify it.
Sign in / Sign upOne scan covers DNS, SSL/TLS certificates, HTTP security headers, redirects, cookies, and email authentication (SPF, DKIM, DMARC). Over 30 checks with details and recommendations.
Create a free account to save your domains. We re-scan daily, probe uptime every 10 minutes, and alert you when something breaks or a certificate nears expiry.
Registered users can run detailed checks for exposed sensitive files (.env, .git), backup files, and open SMTP relays — the things that leak quietly.
Our scanner is deliberately quiet: a few well-paced requests, an honest SiteIsOkBot user agent, and automatic backoff when a firewall pushes back. All checks are read-only and non-destructive. Nothing here can break a site. Intrusive probes are account-gated and rate-limited: this is a monitoring tool, not an attack toolkit. Details in the help page and bot info.
Anonymous one-off scans are free but rate-limited, and results aren't kept. No saved domains, monitoring, history, alerts, or detailed checks. A free account lifts that limitation for one domain; paid plans cover up to 100. See plans & pricing.
The checks map to industry standards — PCI DSS requirements (HTTPS enforcement, HSTS, CAA records, security headers), CA/Browser Forum rules, and RFC best practices — so every result doubles as a readiness checklist. Fix what the scan flags and you're measurably closer to passing a compliance scan. Site is OK is not a certification, but it is a solid, standards-based preparation.