Fast tools for validating and exploiting vulnerabilities in web audits โ no fluff, straight to the point.
Checks whether a domain allows being embedded in an iframe,
indicating missing headers such as X-Frame-Options
and Content-Security-Policy: frame-ancestors.
Sends an authorized spoofed message forged as
security@<domain> to a recipient you own.
Validate SPF, DKIM, and DMARC effectiveness end-to-end.