Website Malware and SEO spam Scanner

Free website malware and SEO spam scanner.

88%
Health

badsite.com

172.237.146.18, 172.237.146.46  ·  Scanned 2026-07-26 10:57:30
1 critical 3 warning 5 good 2 of 3 free scans left
StatusOnline
HTTP status code200
Response time156 ms (Fast)
ProtocolHTTP/2
HTTPS availableYes
Forces HTTPS (redirects http→https)No the insecure http:// version is still reachable
DNS & reachability
Resolves to3 IPv4 · 0 IPv6
IPv6 (AAAA record)No
www vs non-wwwBoth work, same canonical
Routing
RedirectsNone (direct)
Content checks
Fake URL handlingSoft 404 fake URLs return 200 instead of 404
Parked / for-sale pageNot parked
Connection timing breakdown
DNS lookup1 ms
TCP connect48 ms
TLS handshake57 ms
Server processing48 ms
Content transfer2 ms
SSL / TLS Certificate
Certificate presentYes
Trusted & validNo
IssuerLet's Encrypt
Issued tobadsite.com
Also covers (SAN)badsite.com
Expires2026-10-22 (88 days)
TLS versionTLSv1.3
CipherTLS_AES_256_GCM_SHA384 Strong
  • Certificate verification failed: unable to get local issuer certificate
Security Headers (0 ok · 5 weak · 1 missing)
HeaderStateDetail
strict-transport-securityMissingHSTS not set — site is vulnerable to SSL stripping and protocol downgrade attacks
content-security-policyMissingNo Content Security Policy — no structural protection against XSS injection
x-frame-optionsMissingX-Frame-Options not set — site may be vulnerable to clickjacking
x-content-type-optionsMissingX-Content-Type-Options not set — browsers may MIME-sniff and execute malicious content
referrer-policyMissingReferrer-Policy not set — full URLs may leak to third parties via the Referer header
permissions-policyWarningPolicy grants features to all origins (*) — tighten to specific origins or ()
x-xss-protectionOptionalNot set — fine, this header is deprecated (CSP is the modern replacement)
cross-origin-opener-policyOptionalNot set — recommended for cross-origin isolation, but optional
cross-origin-resource-policyOptionalNot set — recommended to prevent your resources being embedded cross-origin
cross-origin-embedder-policyOptionalNot set — optional; needed only for full cross-origin isolation
set-cookieOptionalNo cookies set in the response (nothing to harden)
serverInfoConsider hiding or genericizing this header

No malware signatures matched. The scanned HTML, scripts and links are clean.

No SEO spam, cloaking, hidden links or pharma injection detected.

DNS Blacklists (0 of 5 blocking)
Domain Age & Registration
Domain age26 years (9481 days)
Registered2000-08-09
Expires2026-08-09 (13 days)
RegistrarGoDaddy.com, LLC
WHOIS privacyYes
  • Domain expires in 13 days — renewal urgent
GDPR riskLow
Analytics presentNo
Advertising trackersNo
Session-recording / fingerprintingNo
Privacy policy linkNo
Cookie consent bannerNo
Page HTML size4.6 KB
Server response time156 ms
Compression (gzip/br)Yes
Minified HTMLNo
Browser caching headersNo (max-age 0s)
Total scripts1
External scripts0
Render-blocking scripts0
Stylesheets0
Images0
  • No browser caching headers detected — repeat visitors re-download all assets

No fingerprintable technologies were detected.

External scripts referenced0
Stylesheets referenced0
IP address(es)172.237.146.18, 172.237.146.46
CountryUnknown
Site categoryCloud Service/Hosting

How this tool works?

This tool will scan your website URLs and look for the presence of malware injected on it. It will also look for SPAM seo and other signs of a compromise. We will check multiple blacklists to verify if any of them has the site listed as malicious.

What do we look for?

Spam SEO
Spam Links
Adult content
Gambling and Pharma injection
Iframe injections
Javascript injections
Malicious ads
Fake-AV redirections