SPF record
…—
AI threat engine · online
SecureDomainScore runs an AI-assisted analysis across DNS, SSL, blacklists, WHOIS and 40+ threat signals — and returns a clear A–F trust score in seconds.
Free · no signup · nothing is stored
Full report
—
—
—
Note: port status is checked from the network edge and may not be 100% accurate. ✓ = open, ✕ = closed, ? = unknown.
Analysis layers
Every scan runs the target through independent analysis layers. Each layer reports its own findings; the AI engine weighs them into the final grade.
A, MX, NS and TXT records, plus SPF, DKIM and DMARC. Missing mail authentication is the most common gateway for spoofing.
Certificate validity, issuer reputation, expiry window, protocol versions and HSTS. Weak TLS is treated as a hard penalty.
Presence on spam, malware and phishing blocklists. A single confirmed listing caps the grade at D.
Registration date, registrar reputation and ownership transparency. Very young domains carry structurally higher risk.
ASN reputation, shared-hosting density and geographic anomalies between claimed identity and actual infrastructure.
A language model scores the name itself: typosquats, homoglyphs, brand impersonation and phishing-style keyword patterns.
How it works
Paste any domain — from an email, an invoice, an ad, or a link you're not sure about. No account needed.
DNS, TLS, threat-intel, WHOIS, infrastructure and lexical AI checks execute simultaneously and report raw findings.
The engine resolves conflicting signals into a 0–100 score and an A–F grade, with every contributing factor listed.
Reading the score
Grades C and below always include the specific findings that lowered the score, so you can judge the context — a missing DMARC record is not the same as a live phishing listing.
FAQ
It is a 0–100 rating condensed into an A–F grade, combining DNS health, SSL/TLS configuration, blacklist presence, domain age, WHOIS transparency and AI-detected phishing patterns. A and B are generally safe; D and F signal elevated risk.
More than 40 signals across six layers: DNS and mail authentication (SPF, DKIM, DMARC), SSL/TLS certificates, threat-intelligence blacklists, WHOIS registration data, hosting infrastructure, and lexical AI analysis that detects look-alike and phishing-style names.
Yes. Single-domain scans are free with no account. Bulk scanning and continuous monitoring are available through the API for teams.
Yes — that's the primary use case. Paste the domain from the link into the scanner and review the grade and individual findings before visiting the site or entering credentials.
Run your first scan — it takes less time than reading this sentence twice.
Scan a domain