Skip to content

Checks Overview

Every time you scan a URL, recon-web runs 39 checks across 6 categories. Each check runs in parallel so the entire scan typically completes in under 30 seconds.

Some checks depend on optional API keys. Without any keys configured, 34 checks run out of the box. See Configuration for details on adding API keys.

#CheckCategoryDescription
1SSL CertificateSecurityReads the TLS certificate — issuer, expiry, trust chain
2SSL GradeSecurityLetter grade (A+ to F) from Qualys SSL Labs
3TLS ConfigurationSecurityProtocol version, cipher suites, configuration quality
4HSTSSecurityStrict-Transport-Security header and preload status
5HTTP Security HeadersSecurityScores CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
6Firewall (WAF)SecurityDetects web application firewalls (Cloudflare, AWS WAF, Akamai, etc.)
7security.txtSecurityChecks for a vulnerability disclosure policy file
8ThreatsSecurityCross-references against Google Safe Browsing, URLHaus, PhishTank, Cloudmersive
9Block ListsSecurityChecks 17 DNS-based block lists
10VirusTotalSecurityScans against 70+ antivirus engines
11AbuseIPDBSecurityIP reputation and abuse confidence scoring
12WordPressSecurityDetects WordPress, enumerates plugins/themes, finds misconfigurations
13DNS RecordsDNSResolves A, AAAA, MX, NS, TXT, CNAME, SOA, SRV, PTR
14DNS ProviderDNSIdentifies authoritative nameserver and DoH support
15DNSSECDNSValidates DNSKEY, DS, and RRSIG records
16TXT RecordsDNSParses SPF, DKIM, domain verification entries
17Mail ConfigurationDNSMX records, mail provider identification, SPF/DMARC analysis
18HTTP StatusNetworkStatus code and response time
19HTTP HeadersNetworkFull response header dump
20CookiesNetworkCookie names and security flags
21RedirectsNetworkFull redirect chain with status codes
22Open PortsNetworkScans 33 common TCP ports
23IP AddressNetworkResolves domain to IP
24Server LocationNetworkGeoIP lookup with map display
25TracerouteNetworkNetwork hops to target
26robots.txtContentParses crawler directives
27SitemapContentFinds and parses XML sitemap
28Social TagsContentOpenGraph, Twitter Cards, meta description
29Linked PagesContentInternal and external link analysis
30SEO AuditContentOn-page SEO scoring (0-100)
31WHOISMetaDomain registration details
32Archive HistoryMetaWayback Machine snapshot count and date range
33Domain RankingMetaTranco top-1M popularity ranking
34Legacy RankingMetaCisco Umbrella popularity ranking
35FeaturesMetaBuiltWith feature and technology detection
36Tech StackMetaFramework, CMS, CDN, analytics detection from HTML/headers
37ScreenshotMetaVisual capture of the rendered page
38Carbon FootprintPerformancePage weight, CO2 estimate, green hosting check
39PageSpeedPerformanceGoogle Lighthouse performance, accessibility, best practices, SEO scores
CategoryChecksFocus area
Security12SSL/TLS, headers, WAF, threat intelligence, WordPress
DNS5Records, DNSSEC, provider, email configuration
Network8Status, headers, cookies, ports, traceroute, geolocation
Content5robots.txt, sitemap, social tags, links, SEO
Meta7WHOIS, archives, ranking, tech stack, screenshot
Performance2Carbon footprint, Lighthouse audits

Five checks require optional API keys to function. Without the key, the check is skipped gracefully.

CheckEnvironment variableFree tier
VirusTotalVIRUSTOTAL_API_KEY500 requests/day
AbuseIPDBABUSEIPDB_API_KEY1,000 checks/day
PageSpeedGOOGLE_CLOUD_API_KEYGenerous free quota
FeaturesBUILT_WITH_API_KEYLimited free tier
Threats (partial)CLOUDMERSIVE_API_KEYLimited free tier