Free checks · Free report beta

Free security checks for websites, email domains and APIs.

Check your website’s security headers and HTTPS, your domain’s email settings or an API endpoint’s configuration. Wolf-Agents flags potential issues and explains the findings. When you need to document or share them, use the report for that scan.

Choose what you want to check

Free and without obligation

e.g. wolf-agents.com or www.example.com

Protected by proof of work

Only check domains you operate or have been authorised to assess. By starting the scan you confirm this and accept the usage rules for the free scanners.

A+
A
B
C
D
F
Best grade within the check scope High risk

For IT service providers, in-house IT teams and anyone who needs to discuss technical findings with colleagues or clients.

No installation. No Wolf-Agents account. No email address required during the free report beta.

The checks cover selected settings and signals visible from outside the system. They do not inspect areas behind a login, source code or internal processes.

Three checks for different tasks

Website security settings

How are your security headers, HTTPS and other externally visible settings configured? The web check examines the address you enter, its redirects and selected features including the TLS certificate, domain DNS and delivered HTML.

It does not crawl every page or test your login.

Start the web security check

Email domain settings

What does your domain publish about email sending and transport protection? The email check examines settings such as SPF, discoverable DKIM keys and DMARC, along with signals from reachable mail servers.

It does not read mailboxes or prove reliable delivery or protection against every phishing attack.

Start the email security check

API security settings

What security signals does your publicly reachable API endpoint expose? The API check examines CORS, visible rate-limit headers, server information, HTTP methods, API headers and error responses.

It does not test user permissions or business logic. Rate-limit headers do not prove that a limit will hold under load.

Start the API security check

Only check targets you operate or have been authorised to assess. Scanner usage rules

Put the results to work

A flagged header or DNS record is a starting point. The report records what was checked, what was found and what could not be measured. Explanations, available recommendations and severity information help you assess what to do next.

  • PDF: read, save and share the report as permitted by the applicable terms.
  • DOCX: add your own notes and explanations in Word.
  • CSV: work with the findings table and fill in owners, due dates and implementation status yourself.

All three formats use the same scan. Choosing another file type does not add another test.

Explore the report and file formats

From a check to your next task

  1. Choose and check a target. Start the appropriate check for your domain or URL.
  2. Review the findings. Read the results and any notes about missing or limited measurements. A good grade applies only to the scope of that check.
  3. Save the report and continue your work. Download the available files from the results page. Add your own assessment and pass the relevant information to the people responsible.

Email domains that do not send mail also get PDF, DOCX and CSV reports when the result could be stored for download. A separate scope applies to those checks.

Use it for handovers, changes and internal discussions

Prepare a technical handover

As an IT service provider or agency, record which settings were visible at the time of the check and which questions you want to discuss with your client.

Check again after a change

Save a report before making a change, then run another check afterwards. Compare the two documents yourself. This does not provide an automatic comparison or ongoing monitoring.

Discuss tasks with your team

Use the CSV table to assign findings and record progress in your existing workflow.

Gather technical information for NIS2 work

A report can provide a limited technical record within your documentation. It does not determine whether NIS2 applies to you or whether you comply. Germany’s NIS2 implementation (German)

Understand the settings and make informed changes

Our guides explain web and email configuration, including settings for specific providers. Use them to understand a finding before changing your system.

Web security guides (German) · Email security guides (German)

Working on NIS2? Our NIS2 information for Germany (German) and the NIS2 checklist (German) remain available. A technical scan does not replace a review of legal or organisational requirements.

Try the reports during the free beta

The public checks are free. During the report beta, the available report downloads are also free, with no email address required.

Individual reports and a discounted five-report pack are planned for a later paid launch, without a Wolf-Agents account. The pack is intended for one buyer or company. Sales are not open yet.

Run a free check · Explore the report offer

Understand what the result actually says

The scope is visible. Reports identify the target, scan time and catalogue version. Checks that could not be measured are identified as such.

Measurements and explanations have different origins. Measurements are collected automatically. The explanations were created with AI and have not undergone editorial review. References and ratings support your own review; they do not replace it.

Limits are part of the result. Protective systems in front of a target, connection problems and incomplete measurements can limit the findings. A report captures a point in time. It is not a security certificate.

How results are created

Frequently asked questions

What is free?

The public web, email and API checks and their visible results are free. During the report beta, the available downloads are free too. You do not need a Wolf-Agents account or an email address.

What does a report add to the results I can already see?

It gives you a structured record of the scan to save, annotate and share. PDF, DOCX and CSV use the same measurements. The report does not include additional security tests hidden from the free results.

Does a good result mean everything is secure?

A grade reflects the assessment within that check. Areas outside its scope remain untested, and false findings are possible. When an overall assessment is not sufficiently supported, the report may omit the grade.

Can I use reports for client work?

You can use results from authorised checks as working documents and share completed files within the applicable terms. White-label use and resale as a standalone product are not included as promised rights.

Does downloading again update my scan?

No. A download uses an existing scan result and does not start a new check. Start another scan when you need a new measurement. Save the files you need locally.

Is this a penetration test or NIS2 audit?

No. These automated checks examine a limited technical scope from outside the system. They do not replace manual security testing, an organisational audit or legal assessment.