Core Ripper Ripper
Back to Network Tools

Security Grade

A single-scan composite letter grade for a domain's security posture.

Enter a domain above to run a full security scan.

How grading works
  • Starts at 100 points, deducts per issue found nothing hidden.
  • HTTP security headers (up to 20 pts) missing Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, and others.
  • TLS version (20 pts) server still accepts TLS 1.0/1.1 or older.
  • SSL certificate (10–20 pts) expired or expiring within 14 days.
  • CORS (15 pts) wildcard origin allowed together with credentials.
  • SPF / DMARC (10 pts each) no record found for the domain.
  • DKIM (5 pts) no record at the default selector (often a false negative selectors aren't guessable).
  • DNSSEC (5 pts) zone isn't signed.
  • Cookies (5 pts) missing Secure/HttpOnly flags.