Domain Intelligence,
Instantly.

Scan any domain for security risks, SSL/TLS issues, DNS records, vulnerabilities, and more. All from your device, no data shared with third parties.

v2.0.3
Download on the
App Store
🌐 Try Web Version

Coming soon to macOS, Android, and the Microsoft Store.

27
Scanning Services
7
Scoring Categories
9
Themes
9
Languages + RTL
7
Export Formats
5
Platforms

Everything You Need

Comprehensive domain analysis in a single scan.

🔒

Security Analysis

Evaluate security headers, Reporting-Endpoints, NEL, cookie policies, HTTPS configuration, redirect hygiene, and get an overall security grade with actionable recommendations.

🔐

SSL/TLS Deep Dive

Full certificate chain analysis, protocol version testing, cipher suite evaluation, OCSP stapling detection, mTLS hints, and certificate transparency log lookups.

🌐

DNS, RDAP & Identity

Query all DNS record types. RDAP (RFC 9083) registration data with EPP status analysis, WHOIS fallback, domain risk scoring, and lifecycle volatility monitoring. Accepts domains, IPv4, or IPv6.

🐛

Attack Surface & Exposure

CVE search with EPSS/KEV enrichment, subdomain takeover detection, JS endpoint discovery, third-party dependency inventory, exposed path scanning, and CT remediation guidance.

🏗

Infrastructure Intel

Server technology detection, GeoIP location, hosting provider identification, CDN/WAF detection, reverse DNS analysis, and RPKI route-validation signals.

📈

Risk Scoring

Weighted score across 7 categories: TLS Posture, Web Security, Email Auth, Attack Surface, Identity, Infrastructure, Reputation. A–F grade with a confidence score — you always know how complete the picture is.

🧠

AI Analyst

Plain-language finding explanations and recommendations. Cloud or fully on-device inference (ONNX on native, WebGPU + WASM in the browser) — your data never leaves the device when you choose local mode.

🕒

Scan History & Stats

Sign in with Google, Microsoft, GitHub, or Apple to sync scans across devices. Stats dashboard shows total scans, unique domains, and average score. 90-day retention with automatic drift detection.

🖥

Private Network Scanning

Scan RFC 1918 private IPs and local hosts from the desktop apps. Common port checks (SSH, HTTP, HTTPS, RDP, SMB) with optional full 1–1024 sweep. Hosted surfaces reject private targets to prevent SSRF.

📋

Scan Logs & Diagnostics

Built-in scan log viewer showing per-task timing, phase breakdowns, and error diagnostics. Copy raw logs to clipboard for troubleshooting.

📜

Verbose Exports

Exports grouped by Fail / Warn / Pass with actionable recommendations, category scores, and finding counts across 7 formats including AI Prompt.

Power Workflows

Beyond one-shot scans — continuous monitoring, collaboration, and integrations.

📍

Watch List

Pin up to 20 domains for at-a-glance status. Score, grade, and last-scan time on every entry, with drift indicators when something changes.

Scheduled Rescans

Re-run scans on your cadence — every 24 hours, weekly, or monthly. Backend handles the schedule and notifies you the moment a score drops or a finding shifts.

📊

Diff View

Compare any two scans side-by-side — same domain over time, or two different domains. Powered by the same drift engine the watch list uses.

🔗

Public Share Links

Opt-in, time-limited (default 30 days), revocable read-only links to a rendered report. Perfect for sharing findings with a vendor or auditor.

📱

Webhooks

POST score-drop and drift events to Slack, Teams, Discord, or any generic HTTPS endpoint. JSON payload with the full delta.

🚀

Public REST API

Token-gated /api/v1/scan with per-token rate limits, manageable in Settings. Same scoring engine as the apps — drop into your CI or SOC tooling.

🛡️

Compliance Mappings

Optional control IDs on every finding: NIST CSF, PCI-DSS, HIPAA, SOC 2, ISO 27001. Filter or export by control to feed audit evidence.

🗳️

Severity Overrides

Mark a finding as “accepted risk” per domain with an audit trail. Future scans honor the override but the original signal is preserved.

27 Built-In Services

Every scan runs locally from your device using free, public APIs.

DNS Lookup (10 Record Types)
Advanced DNS (DNSSEC / CAA / Zone Transfer)
WHOIS Lookup
RDAP Lookup (RFC 9083)
TLS Analysis
Certificate Lookup (X.509 / SANs / Chain)
Deep TLS Inspection (ALPN / OCSP / HTTP2-3)
Security Headers
Cookie Security
Email Security (SPF / DKIM / DMARC / MTA-STS / BIMI / DANE / STARTTLS)
Web Server Detection
Web Exposure Scanning (35+ Paths)
Info Disclosure Detection
JS Endpoint Discovery
Third-Party Inventory (50+ Providers)
Reporting Endpoints (NEL / Report-To / CSP)
Infrastructure Intelligence (GeoIP / CDN / WAF)
RPKI & Anycast Analysis
Subdomain Discovery (CT Logs)
CVE Lookup (NVD API)
DNSBL Blacklist Check (8 Providers)
Domain Risk Scoring (Homoglyphs / Typosquats)
Historical Drift Detection
Web Fingerprint (Favicon Hash / DOM Signature)
Security Scoring (7 Categories / A–F Grade)
Your Public Info
Export & Reporting (7 Formats)

Need the full technical checklist? See Technical Details for a complete public coverage matrix.

Choose Your Look

Nine built-in themes, including a WCAG 2.1 accessible option.

🔮 Cyber

Dark neon aesthetic with purple and teal glow effects.

🖥 Matrix

Green-on-black terminal hacker aesthetic.

♿ Accessible

High-contrast colors meeting WCAG 2.1 Level AA standards.

🌊 Midnight

Deep blue ocean with cool cyan accents.

🌅 Sunset

Warm amber and coral tones on dark charcoal.

❄️ Arctic

Cool ice blue with crisp white highlights.

🕵️ Stealth

Muted monochrome for low-profile scanning.

🌹 Rosé

Soft pink and magenta with elegant warmth.

💎 Emerald

Rich green and gold with a luxurious feel.

Export Anywhere

Share results in the format that fits your workflow.

🤖 AI Prompt 📄 JSON 📊 CSV 📝 Markdown 🌐 HTML 📄 Plain Text 📃 PDF

Ready to scan?

Available now on Web and iOS.

Download on the
App Store
🌐 Try the Web App — domainlenspro.app

Coming soon to macOS, Android, and the Microsoft Store.