API
The scanner is a single JSON endpoint. No API key; it's rate-limited per IP (20/min) and only issues bounded, SSRF-guarded requests to the target.
POST /api/scan
Body: { "url": "example.com" }. Returns the observed headers, cookies, redirect chain, TLS certificate and a parsed page summary — you run the grading client-side, or just read the raw fields.
curl -s https://headers.0x6a03448f4d.com/api/scan \
-H 'content-type: application/json' \
-d '{"url":"example.com"}'POST /api/intel
Body: { "domain": "example.com", "dkim": "google" } (dkim optional). Returns DNS/email posture (SPF, DMARC, DKIM, DNSSEC, CAA) and WHOIS/RDAP.
Notes
- Rate limit: 20 requests/min/IP → HTTP 429 with
Retry-After. - Only
http/httpson ports 80/443; private/reserved targets are refused. - Nothing is stored. Scan only sites you are authorised to test.