Privacy controls
CyberFurl can load analytics only after you opt in. Core product features work without analytics consent.
59 professional-grade security tools for email authentication, DNS health, web exposure, SSL/TLS, and threat intelligence — all free, no signup required.
Automate Security Checks with our API & 24/7 Monitoring
Stop running manual checks. CyberFurl Pro gives your engineering and SOC teams full API access to all 59+ tools, bulk domain scanning, webhooks, and continuous real-time alerting.
Validate your domain's mail servers, routing redundancy, STARTTLS support, and overall reachability.
Verify your mail server TLS encryption, protocol support (TLS 1.2+), and certificate validity.
Extract and validate your mail servers' SMTP greetings for RFC compliance.
Run a reverse DNS lookup to ensure your mail server IPs have valid PTR records and pass FCrDNS checks.
Validate ARC support to ensure forwarded emails pass DMARC checks.
Validate DMARC policy, reporting configuration, and enforcement posture for your domain.
Inspect SPF records, included senders, and validation issues before they affect mail delivery.
Expand nested SPF includes to understand the full sender footprint and reduce lookup overhead.
Audit MX readiness, STARTTLS, MTA-STS, TLS-RPT, and DANE in a single unified check.
Combine SPF, DKIM, DMARC, and ARC checks into a single spoofing vulnerability assessment.
Check if a domain is actively rotating its DKIM cryptographic keys to protect against replay attacks.
Check DKIM record availability and signing material to confirm mail authentication is published correctly.
Check whether BIMI branding records are present and aligned with your mail-authentication setup.
Validate MTA-STS records and policy publication to harden inbound SMTP transport.
Inspect TLS reporting records so you can receive delivery-failure telemetry for secure email transport.
Look for TLSA records and review whether DANE is published for your mail infrastructure.
Run an advanced health check on your domain's DNS configuration to ensure stability, proper delegation, and RFC compliance.
Trace the full NS delegation chain, validate glue records, and detect lame delegations for any domain.
Detect wildcard DNS records that catch-all arbitrary subdomains, assess subdomain takeover risks, and validate NSEC zone-walking exposure.
Test DNS-over-HTTPS (DoH) support per RFC 8484, validate TLS certificate chain, and check privacy-preserving resolver configuration.
Monitor authoritative nameservers for downtime or latency spikes.
Perform advanced DNS enumeration to discover subdomains, records, and potential misconfigurations.
Test if your nameservers are vulnerable to DNS amplification and reflection DDoS attacks.
Trace the cryptographic delegation path of your DNS resolution from the root servers down to the authoritative zones.
Check if all authoritative nameservers for a domain return perfectly synchronized DNS records to prevent split-brain issues.
Query DNS records for a domain and review authoritative record data in one place.
Check whether DNSSEC is enabled and review signed-zone indicators returned by the backend.
Review how DNS changes appear across resolvers and detect stale propagation after updates.
Benchmark public resolvers and compare average latency to find the best-performing option.
Measure resolver response times for a domain and identify latency bottlenecks.
Inspect TTL behavior and cache consistency across resolvers for the target domain.
Check whether DNS queries appear exposed or inconsistent based on the backend leak analysis.
Verify whether the target supports DNS over TLS and whether port 853 is reachable.
Check whether the resolver supports EDNS extensions and inspect UDP size or DNSSEC flags.
Check whether the domain appears exposed to zone transfer or related enumeration risk.
Identify the CMS platform (WordPress, Drupal, Joomla, Shopify) version, exposed plugins, and admin paths from HTTP headers and page fingerprints.
Probe 500+ sensitive paths including .git/, .env, phpinfo.php, admin panels, and backup archives — and flag any returning HTTP 200.
Trace the full HTTP redirect chain hop-by-hop, detect mixed HTTP/HTTPS hops, redirect loops, and measure the impact on page load time.
Check WordPress sites for exposed XML-RPC, REST APIs, and vulnerable plugins.
Identify the full web technology stack — framework, CDN, CMS, analytics, A/B tools, and security products — from HTTP headers, HTML, and JavaScript signals.
Test CORS preflight responses, detect wildcard origin reflection, credential leakage risks, and misconfigured Access-Control headers that enable cross-site data theft.
Perform real-time validation against the Google Safe Browsing APIs to check domains for malware and phishing.
Query the AlienVault Open Threat Exchange to see if a domain is associated with active APTs or known hacker campaigns.
Analyze a URL's behavior in an isolated sandbox to detect malicious redirects without risking your own device.
Review public breach exposure signals, provider coverage, and evidence for a target domain.
Discover lookalike domains and review which variants may carry higher brand or phishing risk.
Check the hostname behind a URL or domain against phishing-oriented threat intelligence surfaced in the frontend.
Check whether a domain appears on common DNSBL-style lists exposed through the email-security surface.
Review malware and malicious-domain intelligence already exposed by the frontend for a target domain.
Inspect published CNAME records so you can review whether any third-party references may need closer takeover analysis.
Inspect certificate health, TLS posture, and HTTPS trust signals for a public domain.
Analyze HTTP security headers and review protection gaps that affect browser-side hardening.
Scan open ports for a host and review exposed services that may broaden attack surface.
Retrieve ownership, registrar, and registration lifecycle details for a domain.
Resolve PTR data for an IP or host to understand reverse mapping and infrastructure labeling.
Review hop-by-hop network path data and latency metrics for a public target.
Discover subdomains associated with a target domain and review exposed assets.
Stop running manual checks. CyberFurl Pro gives your engineering and SOC teams full API access to all 59+ tools, bulk domain scanning, webhooks, and continuous real-time alerting.