Edge Grade
Paste a domain. Get an instant letter grade for its edge protection posture. Free, no signup, passive signals only — we never send load to the target.
Want the full picture? The Edge Grade only inspects passive signals.
Run a deep scan with consent →What we measure
Edge Grade aggregates five signals into a single letter grade. We send zero load to the target — no probes that count against a rate limit, no requests that trigger a WAF rule. Every signal is derived from public DNS, public CT logs, and the same single HTTPS connection your browser would make.
CDN / WAF fingerprint
Single HEAD request. Inspect Server, CF-Ray, X-Amz-Cf-Id, X-Azure-Ref, X-Cache, X-Akamai-* headers.
TLS handshake
TLS version, cipher suite, ALPN, certificate issuer + SAN list, HSTS header.
DNS posture
DoH query for A, AAAA, MX, CAA, SPF, DMARC, TXT records. IPv6 present? CAA configured?
Origin concealment
CT log scan. Count distinct subdomains. Cross-reference with CDN fingerprint to estimate origin discoverability.
Public hygiene
security.txt, robots.txt, HTTP/2 negotiation on apex + www, consistent redirect behavior.
Grade scale
Methodology you can audit
The signal logic is calibrated against the DDactic Edge Protection Scorecard. The CDN/WAF fingerprint dictionary, TLS scoring rubric, and DNS posture weights all come from the same per-vendor research. No public claim ships without a JSON receipt.
Edge Grade is in early access. The lookup is live but may return partial results while calibration continues. See the full vendor scorecard for the underlying research.