Beta Now taking testers on iPhone and Android

See what the open web already shows about you.

14 checks across identity, email, domains, and network. Each one ends in a graded result and a short list of what to fix. Built for auditing your own footprint, not other people's.

App Store and Google Play listings arrive with the first release.

Run C95DC791Complete
B
northwind.devScore 85/100 · Email posture
What to do
  • Mail handled by Google Workspace

    1 MX record, lowest priority smtp.google.com.

  • SPF soft-fails unknown senders

    "~all" marks unlisted senders as suspicious rather than rejecting them.

    End the record with -all
  • DMARC policy is reject

    Forged mail that fails authentication is refused.

  • No common DKIM selector found

    24 well-known selectors were checked. Confirm DKIM is enabled with your provider.

  • MTA-STS enforced

    Inbound mail must use a valid TLS connection.

14tools live today
4categories: identity, email, domains, network
30dthen inputs and results are deleted
0analytics or ad SDKs in the app

How it works

Three steps, no guesswork.

01

Enter what is yours

A domain, an email address, a handle, or an IP address that you own or are authorized to assess. Sensitive checks ask you to confirm that before they run.

02

The server does the looking

The app never talks to third parties. Every lookup runs on our server against public data sources, with rate limits and a hard boundary against internal networks.

03

Get findings with fixes

Each result is graded and lists what to change in plain language, down to the exact DNS record, header, or setting.

The catalog

Everything you can check.

Every tool runs on our server against public data sources and returns a graded result with concrete fixes. Nothing logs in anywhere, scans ports, or touches private networks.

Identity

04 tools

Usernames and public profiles tied to you.

  • Username presenceQueuedConsent Which well-known sites have an account under your handle, so you can see what one name links together.
  • Breach exposureConsent Which known data breaches included your email address, and what was taken.
  • Infostealer exposureConsent Whether credentials for your email were captured by info-stealing malware on an infected computer.
  • GitHub exposureConsent What your public GitHub account gives away: contact details, commit emails, keys, and telling repo names.

Email

02 tools

How your email domain is configured and exposed.

  • Email posture Check whether your email domain is protected against spoofing and downgrade.
  • Email address check Whether an address delivers, can be spoofed, is disposable, and has a public Gravatar.

Domains & web

07 tools

DNS records and the public surface of a site.

  • DNS records Inspect the public records that route and verify a domain.
  • Domain surface scanQueuedConsent Queue a compact review of DNS and public web-response signals.
  • Security headers Grade the HTTPS response headers and cookies of a site you run.
  • Domain registration Registrar, expiry, locks, DNSSEC, and whether your contact details are public.
  • Certificates & subdomainsQueuedConsent Find every host name that public certificate logs reveal for your domain, and which still resolve.
  • Archived snapshots See how far back the Internet Archive has copies of your site, including pages you removed.
  • Tech stack Identify the platform, hosting, and third-party scripts a site exposes to visitors.

Network

01 tool

Context for IP addresses and routing.

  • IP address context See what an IP address reveals: who owns it, where it sits, and what its reverse DNS says.
Queued runs in the background and notifies you when done Consent asks you to confirm the identifier is yours

Principles

A self-audit, not a search engine.

01

The app never touches the sources

Your phone talks to one place: our server. The server performs every lookup against 11 public sources, applies rate limits, and refuses anything that resolves to a private network.

02

Thirty days, then gone

Inputs and results stay in your history for 30 days so you can compare before and after a fix. Then a scheduled job deletes them. You can delete any run sooner.

03

Consent before sensitive lookups

Breach, infostealer, and username checks require you to confirm the identifier is yours or that you are authorized. Every run is tied to an account and rate limited.

04

No trackers, no brokers

No analytics SDKs, no ad networks, no data resale. An account exists so your history can sync between devices and queued scans can notify you. That is all it is for.

05

Delete everything in one tap

Account deletion removes your history, saved results, sessions, and device registrations immediately. No email, no waiting period.

Private beta

Find it before someone else does.

Tell us which platform you use and we will send an invite. Testers get every tool, and their feedback shapes the first release.