Free security tools for daily use. The checks run in your browser – the domain checks transmit only the domain name.


🔑 Password Strength Checker

Check the strength of an existing password.

Passwort-Stärke:

ℹ️ Hinweis: Die Passwort-Analyse erfolgt ausschließlich in Ihrem Browser. Das Passwort wird nicht gespeichert oder übertragen. Crack-Zeiten sind Schätzungen für einen Offline-Angriff mit 100 Mrd. Versuchen/Sekunde (z. B. gegen unsalted MD5) — gegen bcrypt oder Argon2 verlängern sich die Werte deutlich.


🔐 Password Generator

Generate cryptographically secure random passwords using crypto.getRandomValues().

Passwort-Stärke:

ℹ️ Hinweis: Alle Passwörter werden ausschließlich in Ihrem Browser generiert. Keine Daten werden an einen Server übertragen.


🌐 Domain, DNS & Mail Security Check

E-mail (SPF, DKIM, DMARC, MX), SSL/HTTPS, and DNS (including DNSSEC, nameserver redundancy, and IPv6) at a glance in 10 seconds: Are all security settings correct for your domain?

E-mail (SPF/DKIM/DMARC), SSL/HTTPS and DNS at a glance: Are all security settings correct for your domain? Checked in 10 seconds – runs in your browser and through our security checks.

ℹ️ Note: The check reads public DNS records via Cloudflare DNS-over-HTTPS and verifies HTTP/SSL reachability. No private credentials or mailbox contents are transmitted.


🧯 Backup Self-Assessment

Will your backups hold up when ransomware hits? Six yes/no questions based on the 3-2-1 rule – with an honest evaluation. Runs entirely locally in your browser.

Six yes/no questions based on the 3-2-1 rule and what ransomware groups attack first. Unchecked counts as "no" – honesty pays off.

ℹ️ Note: Orientation, not a guarantee: the check condenses proven rules (3-2-1-1-0) and does not replace an assessment of your actual environment. All answers stay local in your browser.


🔒 MFA Self-Assessment

Where is multi-factor authentication missing? Eight yes/no questions about the access points attackers target first – with an honest evaluation. Runs entirely locally in your browser.

Eight yes/no questions on multi-factor authentication (MFA) – the single most effective protection against compromised credentials. Unchecked counts as "no" – honesty pays off.

ℹ️ Note: Orientation, not a guarantee: the check condenses proven MFA principles and does not replace an assessment of your actual environment. All answers stay local in your browser.


🛡️ NIS2 Self-Assessment

Not sure whether NIS2 applies to your company? Four questions on sector, role and size – plus a quick check of your security foundation. Runs locally in your browser.

2. Does your company provide any of these services to third parties?

ℹ️ Note: Orientation, not legal advice: this check is based on EU Directive (EU) 2022/2555 ("NIS2"). The binding German implementation (NIS2UmsuCG) may regulate details differently — only an individual assessment is binding. All inputs stay local in your browser.