Strikeguard · by CyberLink Security
Your domain’s external security posture, graded.
Strikeguard reads what your domain already shows the whole internet, grades it from A to F, ranks what needs fixing by impact, and gives equal billing to what you already do well. Verify with your work email, run it in under a minute, keep the report.
- Passive · read-only
- Verified domains only
- Graded in under a minute
- Open source
Step 1 of 3 · Verify your domain
Start with your work email
Strikeguard assesses the domain your email belongs to, so we first confirm you can receive mail there. Personal webmail addresses are not accepted.
The link is valid for 30 minutes. We store only a hash of it, never your address beyond the session, and the report contains only information already visible to the public.
How it works
01
Verify
Enter a work address on the domain. We email a link that proves you can receive mail there; personal webmail is refused.
02
Assess
Strikeguard reads the public configuration of the domain: HTTPS, headers, DNS, email records, certificate logs and registration data. Nothing intrusive is sent.
03
Report
A deterministic score and grade, findings ranked by impact with the exact header or record to set, strengths called out, and an executive summary written for the owner.
What Strikeguard checks
Every check maps to a concrete control you can switch on. Each one is weighted, scored as pass, partial or fail, and shown with evidence and the fix.
Transport security
HTTPS availability, plain-HTTP redirects and HSTS so browsers can never be downgraded.
Browser protections
Content Security Policy, clickjacking defences, MIME sniffing, referrer and permissions policies, mixed content, form targets and script integrity.
Cookie hygiene
Secure, HttpOnly and SameSite flags on every cookie the homepage sets.
DNS hygiene
Name-server redundancy, CAA restrictions on certificate issuance, DNSSEC validation and IPv6.
Email authentication
SPF, DMARC, DKIM, MTA-STS and TLS reporting, so nobody can send mail as you and nobody can read mail sent to you.
Disclosure & hygiene
A valid security.txt so researchers can reach you, and what your robots.txt gives away.
Attack surface (OSINT)
Hostnames in certificate-transparency logs, exposed non-production systems, hosts bypassing your edge network, technology fingerprint, end-of-life libraries, registration expiry and registrar lock.
What Strikeguard never does
- No exploitation, no payloads, no fuzzing and no directory guessing.
- No port scanning or service probing beyond ordinary HTTPS page requests.
- No logins, no credential testing, no interaction with forms.
- No scanning of domains you have not verified you control.
- No storage of your email beyond a two-hour session; reports hold only public data and expire after seven days.
Strikeguard is a posture review, not a penetration test. For an authorised, hands-on assessment with exploitation and remediation support, see our services.
Where the data comes from
Strikeguard reads only public sources, the same ones a careful attacker would start from:
- Public certificate transparency logs, to discover every hostname that has ever been issued a certificate.
- Domain registration data, for expiry and transfer-lock status.
- Public DNS, for name servers, mail authentication and certificate restrictions.
- Published edge-network ranges, to spot hosts that bypass your protection.
- Your own homepage response, for headers, cookies and the stack it reveals.
The checks are deterministic, so the grade is reproducible; the executive summary and remediation plan are generated from those results and labelled as such.
The scanner, the scoring model and this interface are open source so anyone can audit exactly what is sent to their domain. Follow CyberLink Security on GitHub.