Security & transparency

How Pentrawl works

Everything you scan is a domain you own. Here's exactly how our scans work, what we look at, and why each check matters.

How we scan
Is scanning safe for my website?

Yes. Pentrawl only performs passive, read-only checks — the same requests a normal browser or search engine would make. We never attempt to exploit, alter or overload your site. A scan puts no meaningful load on your server.

How does the scan actually work?

Every scan is fully automated — no human ever visits your site. When you enter a domain, Pentrawl looks up its public DNS records and makes a handful of standard web requests to the addresses it already publishes, exactly like a browser loading your homepage or a search engine indexing it. It reads the responses (headers, certificate, page source) and checks a few well-known public paths such as /robots.txt or /wp-login.php. Everything it looks at is information your server already hands out to any visitor on the open internet — we simply collect it, interpret it, and explain what it means.

Do you store my data? For how long?

We store the scan results so you can revisit and share the report. Results are automatically deleted after 30 days. We only store technical data about the public domain — never personal data, and never anything behind a login.

Is it legal to scan a website?

You should only scan domains you own or have explicit permission to test. Pentrawl checks publicly available information — the same data anyone can see — but running a security scan against a site you do not control may still be against the law in your country. Always scan responsibly.

Do you attack my site or just check it?

We only check. Pentrawl inspects your public configuration — DNS records, response headers, certificates and publicly reachable paths. It never launches attacks, brute-forces logins, or tries to break into anything.

What does it cost?

Scanning is free and requires no account. Enter a domain you own and you get the full report in seconds, including the downloadable PDF.

What we scan

Pentrawl checks six layers of your website. Each check links to a full explanation of what it is, why it matters, and how to fix it.

Email authentication
SPF
Controls which servers are allowed to send email for your domain.
Learn more →
DKIM
A cryptographic signature that proves an email really came from you.
Learn more →
DMARC
Decides what happens to emails that fail SPF or DKIM checks.
Learn more →
MX records
The mail servers that receive email for your domain.
Learn more →
Security headers
HSTS
Forces browsers to always connect over secure HTTPS.
Learn more →
Content-Security-Policy
Controls which scripts and resources the browser may load.
Learn more →
X-Frame-Options
Prevents your site being embedded to trick users (clickjacking).
Learn more →
X-Content-Type-Options
Stops the browser from guessing (and misreading) file types.
Learn more →
Referrer-Policy
Controls how much address information leaks to other sites.
Learn more →
Permissions-Policy
Limits access to features like camera, microphone and location.
Learn more →
HTTPS redirect
Checks that visitors on http:// are sent to the secure https:// version.
Learn more →
DNS & domain
A record
The basic record that points your domain to your server.
Learn more →
Name servers
Whether your domain has redundant name servers for reliability.
Learn more →
CAA records
Restricts which authorities may issue certificates for your domain.
Learn more →
IPv6 (AAAA)
Whether your domain is reachable over the modern IPv6 network.
Learn more →
Hosting provider
Identifies which organisation owns the IP your domain resolves to, via public registry data.
Learn more →
SSL / TLS certificate
Certificate validity
Whether your certificate is valid, trusted and not expired.
Learn more →
Expiry
How many days remain before your certificate needs renewing.
Learn more →
Domain coverage
Whether the certificate actually covers your exact domain name.
Learn more →
Issuer
Which certificate authority issued your certificate.
Learn more →
Exposed files & endpoints
Sensitive files
Exposed .env, .git, backups or config files can leak passwords and source code.
Learn more →
Admin & debug endpoints
Publicly reachable admin panels, database tools (phpMyAdmin) and debug interfaces.
Learn more →
Link & source crawl
Scans your page source for exposed API endpoints and leaked keys.
Learn more →
CMS & plugins (WordPress)
Version disclosure
Whether your WordPress version is exposed, revealing known weaknesses.
Learn more →
Vulnerable plugins
Outdated plugins with known CVEs that attackers actively exploit.
Learn more →
User enumeration
Whether usernames can be harvested via the REST API for brute-force attacks.
Learn more →
XML-RPC
An old interface that can be abused for brute-force and amplification attacks.
Learn more →
Login page
Whether the login page is publicly reachable and could be rate-limited.
Learn more →

Ready to check your own site?

Run all these checks in one automated scan.

Scan your website →