CBWATCH
Passive scan · no login · results in seconds

Reads DNS, TLS, and public breach records — nothing that requires the site owner's permission. Results in a few seconds.

Try your own site, or any domain you're curious about.
9 checks · seconds
Free · no signup
EVERY SCAN CHECKS
9categories
Email authenticationSPF · DKIM · DMARC
TLS / SSL certificateValidity · protocol
HTTP security headersHSTS · CSP · more
Breach exposureKnown records
Open ports & servicesExposed surface
Exposed sensitive filesConfig · backups
Software & CMS currencyVersion freshness
Domain expiryDays remaining
security.txt policyDisclosure path
Scanning…
Why CBWatch

Why CBWatch

Most scanners either need an account and permissions, or check things that don't map to how small businesses actually get breached. CBWatch is built around a narrower, more honest premise.

// 01

Nothing to install or approve

Every check reads publicly available information — DNS records, TLS certificates, HTTP headers. No account, no agent on your server, no permission request to approve. Enter a domain, get a result.

// 02

Built around UK compliance Monitoring

Findings map directly to the NCSC/IASME Cyber Essentials control themes, not a generic checklist — useful if you're working toward certification or just want to know where you'd stand. Full readiness mapping is part of paid monitoring; the free scan's findings still feed into it.

// 03

Checks AI-agent exposure, not just search bots Monitoring

A newer, separate check most scanners don't run at all: how your site presents itself to AI crawlers and agents specifically, including a scan for hidden text aimed at manipulating them. Full detail is part of paid monitoring, after domain verification.

// 04

Plain English, not a jargon dump

Every finding explains what's actually wrong and what to do about it — see the full methodology for exactly how the score is calculated.

We use it on ourselves

We use it on ourselves

CBWatch's own live security score badge cbwatch.co.ukLive badge

That's our own live badge, generated by the same scanner, updated on the same schedule as everyone else's. Run the scan yourself →

FAQ

Frequently asked

Is this a real penetration test?

No. It's a passive, external scan of publicly available information — DNS, TLS, HTTP headers, and known breach/exposure data. A penetration test actively probes for vulnerabilities with the owner's permission; CBWatch deliberately never does that. See the methodology for the exact boundary.

Is my data safe if I scan my own domain?

A free scan only reads what's already public about the domain you enter — it isn't stored against you personally. See the Privacy Policy for exactly what's kept and for how long.

Do you need my permission or access to scan a domain?

No — that's the point of passive scanning. Anyone can run the free check on any domain, the same way a browser or mail server reading that site already does. Verifying ownership is only required for the paid monitoring features, via a DNS TXT record you publish yourself.

What happens if I cancel monitoring?

Nothing dramatic — cancel anytime through Stripe's billing portal, no charge if you cancel during the free first month, and your free one-time scan access is unaffected either way. See pricing for the full breakdown.

Limited offer

Try monitoring free for 1 month

Weekly re-scans, instant alerts when something changes, and the full paid feature set — on us for your first month. Cancel anytime, no charge if you cancel before it ends.

£30/month after the trial · cancel anytime via Stripe's billing portal