Skip to content

Free Cybersecurity Checkup Tools

Public tools for checking breach exposure, suspicious files or URLs, and basic website security configuration.

Last reviewed: 2026-07-18

Start here

Check personal email exposure with Have I Been Pwned; website owners can then inspect public HTTPS configuration with SSL Labs or security headers with Mozilla Observatory.

No single scanner can prove that a website, account, file, or device is safe. Each tool below answers a narrower question. Use the result as one signal, read what the tool actually tests, and avoid submitting confidential information to public services.

What Google Safe Browsing does—and does not—prove

Google Safe Browsing Site Status reports whether Google currently identifies dangerous content on a public site. Safe Browsing supports warnings for known or detected malware, unwanted software, and social-engineering threats such as phishing. A warning is a strong reason to stop and investigate.

A clean result is not certification, a penetration test, or proof that a business is legitimate. It does not guarantee that every page, download, advertisement, account flow, or future visit is harmless. Newly compromised content may not yet be classified, and a technically clean site can still sell poor products, misuse data, impersonate a business, or pressure users into unsafe actions. Verify the domain spelling, ownership, contact details, independent reputation, and the specific transaction as well.

Choose the tool that matches the question

  • Is Google currently warning about this public site? Use Safe Browsing Site Status. Do not enter private or tokenized URLs.
  • Is a public server’s HTTPS and TLS configuration sound? Use Qualys SSL Labs Server Test. It analyzes certificates, protocols, cipher support, and public TLS configuration. SSL Labs states that it does not test server exploits or the security of application code.
  • Does a public website send important defensive HTTP headers? Use MDN HTTP Observatory. It evaluates header-related protections and configuration such as CSP, HSTS, cookies, framing, referrer policy, and cross-origin controls.
  • Do I want a fast second opinion on common headers? Use Security Headers. A grade reflects detectable headers, not secure application logic or correct policy design.
  • Has my email address appeared in known breach data? Use Have I Been Pwned. A match identifies reported exposure; it does not reveal which current password is in use. Secure the account directly, change reused passwords, review recovery settings, and enable strong multifactor authentication.
  • How do multiple security engines classify a public URL, domain, file, or hash? Use VirusTotal. Never upload confidential files, private URLs, customer data, unreleased software, or credentials. Submissions and results may be retained or shared according to the service’s policies.

What an A or A+ grade cannot establish

MDN’s own Observatory FAQ explains that a high grade does not test many important issues, including outdated software, SQL injection, vulnerable plugins, authorization, password storage, and other application risks. SSL Labs focuses on TLS rather than the server or business behind it. Security Headers similarly checks response headers, not the effectiveness of every control. A polished score can coexist with vulnerable code, weak accounts, misleading content, or poor operational practices.

A practical website check

  1. Pause before entering credentials or payment information. Confirm the exact domain and how you reached it.
  2. Check Safe Browsing for a known-threat warning.
  3. For a business or important transaction, independently verify ownership, contact information, policies, and reputation.
  4. If you operate the site, use SSL Labs for TLS and Observatory or Security Headers for defensive header configuration.
  5. Use VirusTotal only for non-confidential public material when a multi-engine signal is relevant.
  6. If an account may be exposed, check Have I Been Pwned and secure the account at the provider.
  7. For an active compromise, regulated environment, or business incident, preserve evidence and obtain qualified incident-response help.

Privacy and interpretation warnings

Public scanners may initiate or display scans of a domain and may retain results. Do not test systems you do not own or lack authorization to assess when a service goes beyond passive lookup. A false positive can occur, and a clean result can miss a new or context-specific threat. Compare findings with the responsible tool’s documentation before acting.

Research basis: Search Console shows Google Safe Browsing queries near page one and MDN HTTP Observatory page-level demand. Reviewed against Google Safe Browsing, Qualys SSL Labs, MDN Observatory, Have I Been Pwned, VirusTotal, and Security Headers on August 22, 2026.

Suggested path

Open the resource that best matches your immediate task. Read its own documentation and limitations, try it with low-risk material, and keep notes on what worked.

Reviewed Resources

  • Have I Been Pwned

    Checking whether an email appears in known breach data

    Breach lookup Free Best for: Checking whether an email appears in known breach data Checked: 2026-07-21 Updated: July 20, 2026 Visit resource
  • VirusTotal

    Comparing a non-confidential file, URL, domain, or hash across security engines

    Security scanner Free Best for: Comparing a non-confidential file, URL, domain, or hash across security engines Checked: 2026-07-21 Updated: July 20, 2026 Visit resource
  • Qualys SSL Labs Server Test

    Reviewing the public TLS and HTTPS configuration of a website server

    Website test Free Best for: Reviewing the public TLS and HTTPS configuration of a website server Checked: 2026-07-21 Updated: July 20, 2026 Visit resource
  • MDN HTTP Observatory

    Reviewing public HTTP security headers and related website configuration

    Website test Free Best for: Reviewing public HTTP security headers and related website configuration Checked: 2026-07-21 Updated: July 20, 2026 Visit resource
  • Security Headers

    Quickly checking whether a public website sends common defensive headers

    Website test Free Best for: Quickly checking whether a public website sends common defensive headers Checked: 2026-07-21 Updated: July 20, 2026 Visit resource
  • Google Safe Browsing Site Status

    Checking whether Google currently flags a public site for unsafe content

    Reputation lookup Free Best for: Checking whether Google currently flags a public site for unsafe content Checked: 2026-07-21 Updated: July 20, 2026 Visit resource
  • CISA Cyber Security Evaluation Tool

    Structured cybersecurity self-assessment for organizations and operational environments

    Desktop assessment tool Free Best for: Structured cybersecurity self-assessment for organizations and operational environments Checked: 2026-07-21 Updated: July 20, 2026 Visit resource
  • CISA Known Exploited Vulnerabilities Catalog

    Prioritizing vulnerabilities known to be exploited in real attacks

    Security catalog Free Best for: Prioritizing vulnerabilities known to be exploited in real attacks Checked: 2026-07-21 Updated: July 20, 2026 Visit resource
  • NIST Cybersecurity Framework 2.0

    Organizing an organization-wide cybersecurity review and improvement plan

    Assessment framework Free Best for: Organizing an organization-wide cybersecurity review and improvement plan Checked: 2026-07-21 Updated: July 20, 2026 Visit resource
  • Internet.nl

    Checking modern internet standards for a website, mail domain, or connection

    Website and email test Free Best for: Checking modern internet standards for a website, mail domain, or connection Checked: 2026-07-21 Updated: July 20, 2026 Visit resource

Related topics

Suggest a resource or correction