operate
Launch Readiness + Free Security Tools
Four free checks for any site. A grade only the owner can publish.
What you get
Four checks, no signup
Security headers, email security (SPF, DMARC, DNSSEC, CAA), exposed source maps and CORS — passive GET and DNS lookups only, no attack traffic, with the fix for every finding.
A grade only the owner can publish
Prove you control the domain with a DNS record, a file or a meta tag and you get a letter grade, a shareable report and a Verified badge. Nobody can publish a grade about a site they don't own.
Kept honest after you share it
Shared grades re-run daily and re-prove ownership every time. Remove the verification and the public report comes down on its own.
How it works
- 1
Run any single check at ziploom.dev/tools — findings and fixes, no account.
- 2
For Launch Readiness, add the verification record to your domain and confirm your email.
- 3
ZipLoom runs every check and returns a letter grade — or withholds it if any check could not complete.
- 4
Share an A or B grade as a public report and badge; it re-verifies daily.
What this check inspects
HSTS, Content-Security-Policy quality, clickjacking, cookie and referrer policy on your live URL.
SPF, DMARC, DNSSEC and CAA — graded on your registrable domain, never on a shared hosting platform's records.
JavaScript source maps served in production, which hand out your original source.
CORS responses that reflect any origin.
What it means when this fails
These are the issues a customer's security questionnaire, a penetration tester or an attacker finds in the first five minutes — and they are all visible from outside, so assume someone has already looked.
Questions
- Does the free check attack my site?
- No. It only makes the same GET requests and DNS lookups a browser or mail server would.
- Why won't the single checks give me a grade?
- A grade about a site is only published for a verified owner. The single checks give you every finding and fix without one.
Related features
Security Header Audit
Every security header on your live URL, graded — HSTS, CSP, cookie flags, WAF fingerprint.
Learn moreDNS, Email Auth & Takeover Guard
DNSSEC, CAA, SPF/DKIM/DMARC — and dangling records that let someone claim your subdomain.
Learn moreLive Posture Scan on Your Deployed URL
External header, TLS, cookie, and DNS checks against the running site.
Learn more