Feranor
Consulting
Resilience check
What your domain gives away
We fetch your root URL, open a TLS connection to read your certificate, and check whether plain HTTP redirects to HTTPS. Everything reported comes from what your server already tells anyone who asks.
What gets checked
Certificate validity and expiry, whether plain HTTP redirects to HTTPS, HSTS.
Content-Security-Policy, X-Content-Type-Options, clickjacking protection, Referrer-Policy.
How many addresses your domain resolves to, IPv6 availability, whether a CDN sits in front.
Time to reach your root URL, cache directives.
Redirect chain length, software versions exposed in headers.
What it doesn't check
This reads your root URL. It says nothing about the systems behind it, your data layer, your failure modes under load, or how your services behave when a dependency goes down. A clean result here means your front door is tidy, not that your architecture holds.
Three requests. - Your root URL, one per redirect hop, and one on port 80. Nothing is crawled, no forms are submitted, no JavaScript runs.
Results are kept. - Each check is stored against the domain so it can be compared with later ones. Domain and result only.
Our crawler. - Requests come from FeranorBot. How to control it