Sign up for a free account at mbguards.com/signup. No credit card required to get started.
Navigate to the dashboard and click "Add Website". Enter your domain name (e.g., example.com).
Add a DNS TXT record to verify you own the domain. We'll provide a unique verification code that you add to your DNS settings.
Once verified, click "Scan" to analyze your website's security. Results are available within minutes.
We check for essential HTTP security headers including Content-Security-Policy, Strict-Transport-Security (HSTS), X-Frame-Options, X-Content-Type-Options, and more.
Verify your SSL certificate is valid, check expiration dates, and ensure proper certificate chain configuration.
Check for SPF, DMARC, and DNSSEC records to protect against email spoofing and DNS-based attacks.
Identify CMS platforms, frameworks, analytics tools, and other technologies running on your website to understand your attack surface.
Scan for commonly exposed files like .env, .git, backup files, and admin panels that could leak sensitive information.
MBGuards provides both a letter grade (A+ to F) and a risk score (0-100) for your website.
| Grade | Risk Score | Meaning |
|---|---|---|
| A+ | 0-5 | Excellent security posture |
| A | 6-15 | Very good security |
| B | 16-30 | Good with minor issues |
| C | 31-50 | Moderate concerns |
| D | 51-70 | Significant issues |
| F | 71-100 | Critical problems |
Pro and Enterprise users can configure automated scheduled scans:
Configure your schedule from the Dashboard under "Scheduled Scans".
Stay informed with email notifications (Pro and Enterprise plans):
Manage your notification preferences at /alerts.
Yes! MBGuards uses passive, non-intrusive scanning that won't affect your site's performance or trigger security alerts. We only analyze publicly accessible information.
Domain verification ensures you can only scan websites you own or have permission to scan. This protects against unauthorized scanning of third-party websites.
Most scans complete within 1-2 minutes. Complex sites with many technologies may take slightly longer.
No. You must verify domain ownership before scanning. This is an industry-standard security practice to prevent abuse.