CyberSpy scans the domains you verify you own — ports, TLS, security headers, exposed files, CMS fingerprints and DNS hygiene — and turns them into findings you can actually fix. No noise. No guesswork.
Every scan runs a full battery of non-intrusive tests and rolls them into a prioritized, fixable report.
Concurrent TCP scan that flags risky database, cache and admin ports reachable from the internet.
Certificate validity, expiry windows and self-signed detection so HTTPS never quietly breaks.
HSTS, CSP, X-Frame-Options, cookies and CORS — graded with exactly what to add.
Detects leaked .env, .git, backups and config dumps — with smart soft-404 filtering to kill false positives.
Identifies WordPress, Laravel and exposed admin panels, and flags version disclosure.
SPF and DMARC policy checks so your domain is harder to spoof.
CyberSpy only scans assets you prove you control — the responsible, legal way to test.
Register a domain or subdomain you own and pick a verification method: DNS TXT, a file, or a meta tag.
Publish the token we generate. One click confirms it — and unlocks scanning for that target only.
Run quick or full scans, pick exactly which checks, and get a prioritized report with remediation steps.
Create a free account, verify a domain, and run your first scan today.
Start free scan