Settings

Theme

Show HN: DomainOptic – Free Web Security audit that scans what other tools miss

domainoptic.com

1 points by renbuilds 3 months ago · 0 comments · 1 min read

Reader

I built DomainOptic after almost shipping my Stripe key in a production bundle.

It runs 6 checks in a few seconds:

* SSL Certificate - validity, expiration, protocol - DNS Health - SPF, DKIM, DMARC (email spoofing protection) * Security Headers - CSP, HSTS, X-Frame-Options * Blacklist Status - spam/malware list checks * Secret Scanner - finds leaked API keys in public JS bundles (AWS, Stripe, Firebase, etc.) * Ghost API Hunter - exposed Swagger docs, GraphQL endpoints, debug routes

Every scan gets A+ to F grades with plain English explanations as to why you'd care.

The last two are the differentiators, most SSL checkers exist, but few tools passively scan your frontend for shipped secrets or forgotten /api endpoints.

Looking for feedback on false positive rates and what other checks would be useful.

No comments yet.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection