Focused diagnostics
SysGlass tool directory
Run focused checks for DNS, TLS, mail deliverability, web security, network reachability, IP intelligence, and exposed services. Every tool returns measured data, a verdict, evidence, and practical fixes.
54 focused checks
Tool directory
Search DNS, TLS, mail, web, network, security, discovery and IP diagnostics.
54 of 54 tools shown
DNS
6DNS Lookup
Free online DNS lookup. Query A, AAAA, MX, TXT, NS, CNAME, PTR and SRV records for any domain through a public resolver, with a clear pass/fail verdict and a fix tip.
DNSSEC Validation
Free DNSSEC validation. Check if a domain is DNSSEC-signed and its chain of trust validates (DNSKEY, DS, algorithms), and catch broken/bogus DNSSEC that makes a domain unresolvable.
Nameserver & Zone Health
Free nameserver and DNS zone health check: are your nameservers reachable, IPv6-capable, EDNS/TCP-ready and consistent, are SOA timers sane, and do your records have clean TTLs (no too-low / mixed TTLs, MX-to-CNAME, or NS/MX pointing at an IP)?
DNS Delegation Health
Free DNS delegation check. Compares the NS set your registry hands out against your zone's own NS records, verifies glue for in-bailiwick nameservers, detects lame delegations, and confirms the DS↔DNSKEY chain — the registry-side problems other checks miss.
DNS Propagation / Multi-Resolver
Free DNS propagation checker. Query a domain's A, AAAA and NS records from multiple public resolvers (Google, Cloudflare, Quad9, OpenDNS) at once to see whether a DNS change has propagated, or to spot GeoDNS / split-horizon and inconsistent answers across resolvers.
Open DNS Resolver Test
Free open DNS resolver test. Check whether a nameserver on UDP/53 recursively answers for domains it isn't authoritative for, amplifies ANY queries for DDoS reflection, allows AXFR zone transfers, or leaks its version.bind — with fixes.
TLS
2SSL Certificate Checker
Free SSL/TLS certificate checker: see issuer, SAN, expiry date and days left, negotiated TLS version, and whether a cert auto-renews or needs manual renewal.
Deep TLS Audit
Free deep TLS audit. See which TLS versions a host offers (1.0/1.1/1.2/1.3), the cipher it negotiates on each, whether it still accepts weak ciphers, and an overall A–F grade with fixes.
Security
7TLS Configuration Audit
Free TLS configuration audit. Test a server for Heartbleed, POODLE, DROWN, FREAK, Logjam, Sweet32, BEAST and CCS Injection, plus OCSP/CRL certificate revocation — with a clear verdict and fixes.
Exposed Files Check
Free exposed files check. Check a website for publicly readable .env, .git, .svn/.hg, Spring Boot Actuator, Tomcat Manager, phpinfo, server-status and swagger files that leak secrets and source code — with a fix.
CORS Configuration Audit
Free CORS configuration audit. Test whether a website or API reflects an arbitrary Origin, trusts the null origin, allows credentials, or has a bypassable allowlist — the cross-origin bugs that let any site read your authenticated responses.
Open Redirect Check
Free open redirect check. Test whether a login, logout or tracking endpoint lets a request parameter (next, url, redirect_uri, return…) send visitors to an arbitrary external site — the flaw behind phishing links and OAuth token theft.
GraphQL Exposure Audit
Free GraphQL exposure audit. Check whether a GraphQL API still has schema introspection enabled in production or leaves an interactive GraphiQL / Apollo Playground IDE exposed — and how to lock both down.
CVE Lookup
Free CVE lookup. Enter a product and version (or a CPE) and see the known CVEs published for it, each with its CVSS score, severity and a link to the NVD record. Data comes from the public NVD vulnerability feed.
IP / Host Exposure Audit
Free live IP/host exposure scan. Enter an IP or hostname and SysGlass scans it in real time and shows what is actually exposed: open ports, the detected service and version on each, the CVEs it's affected by (confirmed-exposed vs version-vulnerable), DDoS-amplification vectors, exposed gateways/admin panels, and TLS/header issues — with exact fixes.
Domain
1Web
3HTTP Header Checker
Check any site's HTTP response and security headers free. See status code, protocol, response time, and missing HSTS, CSP, X-Frame-Options and more.
Web Server Audit
Free web server audit. Follow the redirect chain, grade the HTTP security headers (A–F), fingerprint the server/stack, and flag insecure cookies — with exact fixes.
Deep CSP & Header Report
Free deep CSP and security-header report. Renders the page in a real browser to evaluate the effective Content-Security-Policy, grades the headers, and lists concrete directive-level fixes.
Network
11TCP Ping
Free online TCP ping — check whether a host and port (default 443) are reachable and measure round-trip latency. A TCP connect test, not ICMP. No install.
Open Ports Check
Free online open-port check. Check whether common TCP ports (SSH, HTTP, HTTPS, SMTP, RDP, MySQL, Redis...) are open on a host, and get warned about exposed sensitive services.
Service Inspector
Scan a host's open ports (TCP 1-1024 + key UDP) and deep-inspect each live service — SSH algorithms, SMTP/IMAP TLS, DNS open-resolver, SMB signing, SNMP, exposed databases — with a risk badge and the exact fix for every issue.
SSH Hardening Check
Free SSH server security audit. SysGlass TCP 22 for the banner/version, host-key, key-exchange, cipher and MAC algorithms, weak/legacy primitives, the obsolete SSH protocol 1, and the 'none' cipher — with concrete hardening fixes.
SMB Security Check
Free SMB security check on TCP/445. See whether Windows file sharing is exposed to the internet, the negotiated dialect, whether the obsolete SMBv1 is enabled, and whether message signing is required — the surface behind EternalBlue, WannaCry and NTLM relay.
SNMP Exposure Check
Free SNMP exposure check on UDP/161. See whether a device answers the default 'public' community, runs clear-text SNMP v1/v2c, is reachable from outside the management network, or can be used as a UDP amplification source — with SNMPv3 fixes.
NTP Amplification Check
Free NTP amplification check on UDP/123. Test whether a time server answers the mode-7 monlist query (CVE-2013-5211) or unauthenticated mode-6 control queries — high-impact DDoS reflection sources — and see the measured amplification factor, with fixes.
IPMI / BMC Exposure Check
Free IPMI / BMC exposure check on UDP/623. Detect an internet-facing server management plane (iDRAC, iLO, IMM, Supermicro) and the cipher-suite-0 backdoor, anonymous login, and the RAKP hash-disclosure flaw (CVE-2013-4786) — with isolation fixes.
Traceroute
Free online traceroute from a remote server. Trace the network path to any host or IP and see every hop's address, reverse DNS, and round-trip time. Runs from our nodes (IPv4 & IPv6) — no client needed.
MTR (My Traceroute)
Free online MTR from a remote server. Combines traceroute and ping: probes every hop multiple times and reports per-hop packet loss and latency (last, avg, best, worst, jitter) for IPv4 and IPv6.
BGP Looking Glass
Free BGP looking glass. Enter an IP, prefix, ASN or domain to see the announced prefix, origin AS and holder, RPKI validity, global routing visibility (RIS peers), sample AS paths, and the managing RIR (ARIN, RIPE NCC, APNIC, LACNIC, AFRINIC).
IP
4Reverse DNS (PTR)
Free reverse DNS / PTR lookup for IPv4 and IPv6. See the hostname an IP resolves to, plus the exact reverse-DNS name (in-addr.arpa / ip6.arpa) to publish a PTR record at.
PTR Record Generator
Free PTR record generator. Enter an IPv4 or IPv6 address to get the exact reverse-DNS name (in-addr.arpa / ip6.arpa), a ready-to-paste PTR record, and the delegated reverse zone (/24 or /64). No more hand-writing reversed IPv6 nibbles.
IP Geolocation
Free IP geolocation lookup. Find the approximate city, country, coordinates, timezone, network (ASN/org) and ISP for any IPv4 or IPv6 address.
ASN Lookup
Free ASN lookup with AS reputation. Find which Autonomous System (AS number, network name, prefix, country) announces any IP, plus whether the AS is on Spamhaus ASN-DROP or UCEPROTECT Level 3.
Discovery
3Subdomain Finder
Free subdomain finder that lists every subdomain a public CA has issued a certificate for, pulled live from Certificate Transparency logs. Same data as crt.sh.
Subdomain Takeover Audit
Free subdomain takeover checker. Detects when a host's CNAME points at a third-party service (GitHub Pages, Heroku, S3, Azure…) whose resource is unclaimed — letting an attacker hijack your subdomain.
Origin Exposure Check
Free origin exposure check. See whether your real origin server IP leaks past your CDN/WAF (Cloudflare) through Certificate-Transparency subdomains, A/AAAA records, MX hosts or SPF — and whether a leaked IP actually serves the site when contacted directly, defeating the WAF.
Email Auth Checker
Free SPF, DMARC and DKIM checker. Enter a domain to test MX, SPF, DMARC policy and DKIM selectors, see if your mail can be spoofed, and get concrete fixes.
SPF Checker
Free SPF checker. Validate a domain's SPF record, count the RFC 7208 DNS-lookup limit (max 10), and check the all-qualifier — with the exact fix.
SPF IP Tester
Free SPF IP tester. Enter a domain and a sending IP to see the exact SPF result a receiving mail server would record — pass, fail, softfail, neutral or permerror — and the mechanism that matched.
DMARC Checker
Free DMARC checker. Look up a domain's DMARC record and read its policy (none/quarantine/reject), subdomain policy, percentage, alignment and report address.
BIMI Checker
Free BIMI checker. Look up a domain's BIMI record, its SVG logo and Verified Mark Certificate (VMC) — and what's needed to show your brand logo in inboxes.
DKIM Checker
Free DKIM checker. Look up a domain's DKIM public key by selector, see the key type and bit length (1024 vs 2048), and detect testing/revoked keys — with the fix.
MTA-STS Checker
Free MTA-STS checker. Validate the _mta-sts TXT record and the published policy file (mode, covered MX, max_age) so inbound SMTP requires TLS — with the exact fix.
TLS-RPT Checker
Free TLS-RPT checker. Validate the _smtp._tls TXT record (RFC 8460) and its rua report destinations so you learn when senders fail TLS/MTA-STS — with the fix.
DANE / TLSA Checker
Free DANE checker. Look up TLSA records at _25._tcp.<mx> for every MX host (RFC 7672) so senders can pin TLS and refuse downgrade — with the exact fix.
Blacklist Check
Free DNSBL blacklist check plus a StopForumSpam spam score. Test an IPv4 or domain against 13 blacklists (Spamhaus ZEN, SpamCop, Barracuda, SORBS, PSBL and more) and see the IP's 0-100 spam confidence.
SMTP Server Test
Free SMTP server test. Connect to a mail server (or a domain's MX), read its ESMTP capabilities, check STARTTLS, reverse DNS, and run a safe open-relay test — with fixes.
Mail Server (MX) Health
Free mail server (MX) health check. For every MX host of a domain it verifies forward-confirmed reverse DNS (FCrDNS / PTR match), STARTTLS with certificate validity and TLS version, and the SMTP banner — the things receivers judge before accepting your mail. Works for Microsoft 365 and Google Workspace too.
Bounce / NDR Analyzer
Free email bounce analyzer. Paste a non-delivery report (NDR) and get the SMTP reply + enhanced status code decoded — the real cause (auth, reputation, content, rate limit, bad recipient) and the exact fix.
Email Content & Link Safety
Paste a raw email to check it for phishing signals (mismatched links, look-alike domains), content/spam risk, tracking pixels, and bulk-sender compliance — List-Unsubscribe and RFC 8058 one-click — with per-receiver guidance.
URL / Link Reputation
Free URL reputation checker. Test a link or domain against the Spamhaus DBL, SURBL and URIBL blocklists, follow its redirect chain, and detect shorteners — so spammy links don't sink your email.
DMARC Report Analyzer
Free DMARC report analyzer. Paste a DMARC aggregate (rua) XML report and see who's sending as your domain: pass/fail rates and the exact source IPs failing alignment — so you can safely reach p=reject.
Mail Record Generator
Free generator for mail DNS records. Enter your domain and get a correct, copy-paste SPF, DMARC, DKIM, MTA-STS, TLS-RPT or BIMI record, the exact name to publish it at, and the rollout steps.