What I Scan
- Open ports on your domain (standard 15-port sweep — what services are publicly listening)
- Service banners (the version information your software announces when a connection is made)
- TLS/SSL certificate validity, expiry, and protocol versions (encrypted connection check)
- HTTP security headers (HSTS, CSP, X-Frame-Options — browser protection controls)
- DNS records (publicly resolvable subdomains and email security records)
- Known software vulnerabilities matching the reported service versions (CVE database)