Most “free checkers” are a lead form with a spinner. These are the real backends our paying customers use, opened up for a few runs a day — a website safety check, an email header reader, and a PDF X-ray that recovers what an earlier version of the file used to say.
Each one runs on its own, right in the page. Results appear in seconds; nothing is stored.
Paste a link. Get registration age, DNS and mail records, the live certificate, security headers and a corroborated safety verdict.
Check a linkPaste the raw headers. Read SPF, DKIM and DMARC, walk the relay chain, and see the display-name and reply-to tricks behind most invoice fraud.
Read a headerUpload a PDF. See saved revisions, values an earlier version carried, hidden layers, and the structural traces an edit leaves behind.
X-ray a PDFA full document scan reads five layers, cross-checks them against each other, and produces a reasoned verdict on everything it found. That is the product, and it lives behind an account.
The three tools on this page answer narrower questions, and they answer them from evidence you can point at. They resolve DNS. They complete a TLS handshake and read the certificate the server actually presents. They pull the domain's public registration record. They parse an email's Received chain and its authentication results. They walk a PDF's cross-reference tables and reconstruct the revisions still sitting inside the file. Every one of those is a fact the internet or the file itself will confirm — which is why we can put them in front of anyone.
The daily allowance is there to keep them quick. A URL check makes a dozen live network requests and the X-Ray runs a dedicated analysis worker, so the capacity is shared and the limit is what keeps the queue moving.
Everything that needs a document read end to end: the five-layer forensic scan, the plain-English verdict and 0–100 risk score, the AI reasoning layer that explains each finding, saved and shareable reports, page screenshots on URL checks, the metadata and image-forensics labs, side-by-side document comparison, and the automation that runs all of it for you. This page is the doorway; that is the workspace.
Nothing is saved. The free tools hold your input for the length of the request and drop it with the response — no stored report, no archived file, no record of the URL, the message or the filename. The only thing we keep is an anonymous count so the daily allowance means something, and it is a number, not an identity.
Everything you see comes from deterministic analysis: public registration records, live DNS and TLS handshakes, header parsing and PDF structure. The same engines answer the same way whether or not you have an account.
We publish what we find in real documents. No gated PDFs, no newsletter wall.
Six checks that actually work, in the order a document examiner runs them.
Related, not the same — and the difference decides which control stops it.
What the two metadata records reveal, and why editors leave them disagreeing.
Yes. Three of them run with no account at all — you get a few full-strength checks every day, and nothing is stored. They are the same backends the paid product uses, not cut-down demos.
To keep them quick. A URL check makes a dozen live network requests and the PDF X-Ray runs a dedicated analysis worker, so capacity is shared across everyone using them. A free account lifts the limit.
No. The free tools process your input inside the request and discard it with the response. Nothing is written to a report, a vault, or a log of what you analyzed.
Full five-layer document scans with a plain-English verdict, saved reports you can share, page screenshots on URL checks, the metadata and image-forensics labs, document comparison, PDF tools, and automation. No card required.
A free account turns three quick checks into a full forensic workspace.