Security work lives and dies on the details | a missing header, an expiring certificate, an SPF record that silently fails. These tools let you check posture and generate the artefacts that harden it, without installing anything or handing data to a third party.
Grade a site's security headers and TLS, decode a certificate or JWT, analyse SPF, DKIM and DMARC in one pass, generate strong secrets and hashes, or score a vulnerability with CVSS. The client-side utilities never transmit your input; the diagnostic checks query only the target you name. CISOs, security engineers and IT teams use them during audits, incident response, configuration reviews and board-level risk conversations.
All Security & Compliance tools
22 toolsSSL/TLS Checker
Certificate chain, expiry, protocols and issues.
Certificate Decoder
Decode a PEM/CSR and read every field.
Security Headers Analyzer
Grade HSTS, CSP, X-Frame-Options and more.
HTTP Header Viewer
Inspect raw response headers and redirects.
Email Security Analyzer
SPF, DKIM, DMARC, MTA-STS, BIMI in one report.
SPF Record Generator
Build a valid SPF TXT record visually.
DMARC Record Generator
Generate a DMARC policy with reporting.
Password Generator
Strong random passwords with full control.
Passphrase Generator
Memorable diceware-style passphrases.
Password Strength Tester
Entropy and realistic crack-time estimate.
Hash Generator
MD5, SHA-1/256/384/512 of text or files.
HMAC Generator
Keyed HMAC signatures with any algorithm.
Bcrypt Generator
Hash and verify passwords with bcrypt.
.htpasswd Generator
Create Apache/Nginx basic-auth credentials.
Hash Identifier
Guess the algorithm behind a hash string.
JWT Decoder
Decode and inspect JSON Web Token claims.
UUID / GUID Generator
Generate v4 and v7 UUIDs in bulk.
API Key Generator
Random tokens, secrets and API keys.
CVSS Calculator
Score vulnerabilities with CVSS 3.1.
CSP Builder
Compose a Content-Security-Policy header.
security.txt Generator
RFC 9116 vulnerability disclosure file.
URL Redirect Tracer
Unwrap shortened links and follow redirects.