Every tool in one place. Filter by category or search.
Inspect your own connection: IP address, IPv6 support, and speed.
Your real public IP address as seen by the internet, with ISP, location and network details.
Instantly check whether your connection supports IPv6. See your address, type, /64 prefix and ISP details.
Test your internet download speed, upload speed, and latency directly in the browser.
Query, validate, and debug DNS records: lookups, propagation, health checks, DNSSEC, DANE, and zone builders.
Query any DNS record type for any domain - A, AAAA, MX, TXT, CNAME, NS, SOA, CAA. Results come from Cloudflare's global DNS resolver (1.1.1.1).
Check if your DNS changes have propagated globally. Queries 6 public resolvers across Google, Cloudflare, NextDNS, dns.sb, Tiarap, and DNSPod to compare results.
Audit the DNS setup of any domain and get a letter grade with specific fix hints for each failing check.
Resolve and analyze the SPF record for any domain - including recursive include chains, DNS lookup counting, and policy violation detection.
Look up the PTR (reverse DNS) record for any IPv4 address. PTR records map IPs back to hostnames.
Check which Certificate Authorities are permitted to issue SSL/TLS certificates for a domain.
Look up DNS SRV records to discover service endpoints. Used by SIP, XMPP, Matrix, Minecraft, Kubernetes and more.
Trace DNS resolution step-by-step from root nameservers to the final answer.
Compare DNS results across four public resolvers and test for NXDOMAIN hijacking - a sign of ISP DNS interception.
Look up TLSA DNS records for DANE (DNS-Based Authentication of Named Entities) across HTTPS, SMTP, and SMTPS services.
Verify whether a domain has DNSSEC enabled and check the full chain of trust from root to authoritative nameserver.
Build a valid SPF TXT record. Select your email providers, add custom includes and IP ranges, then copy the record into your DNS.
Generate an RSA key pair for DKIM email signing. The public key goes into your DNS as a TXT record. Keep the private key on your mail server.
Compare two DNS zone files. Paste your original and modified zones to see exactly which records changed. Runs entirely in your browser.
Generate a BIND-format reverse DNS zone file from a subnet CIDR. Supports standard /8, /16, /24 subnets and classless /25-/31 delegation per RFC 2317.
Subnet math, CIDR, VLAN, MTU, bandwidth, and binary/hex conversions. All client-side, no API needed.
Enter any IPv4 address and CIDR prefix or dotted subnet mask like 255.255.255.0. Network address, broadcast, host range, and wildcard mask calculate instantly. The built-in visual subnet calculator lets you split and rejoin blocks interactively.
List every IP address in a subnet block. Enter a network address and CIDR prefix - usable hosts, network and broadcast addresses are highlighted.
Allocate subnets of different sizes from one address block. Enter your base network and the number of hosts each subnet needs.
Design your network segmentation - assign VLAN IDs, names, and subnets with live validation and CSV export.
Convert network speeds between Mbps, Gbps, MB/s and more. Estimate file transfer time for any file size and link speed, and calculate link utilisation percentage.
Enter an IPv6 address and prefix to calculate the network address, host range, total address count, and 128-bit binary breakdown.
Convert any IPv4 address to its 32-bit binary representation - and back. Click any bit to toggle it and watch the IP address update instantly.
Aggregate multiple IPv4 CIDR blocks into the smallest single supernet that covers all of them. Useful for route summarisation, firewall rule consolidation, and IP address planning.
Paste a list of IPv4 CIDR blocks and merge overlapping or adjacent ranges into the smallest possible set of non-overlapping prefixes.
Convert a CIDR block to its first and last IP, or find the smallest CIDR that covers two IP addresses.
Split a CIDR block into equal subnets by count or prefix length.
Convert IPv4 to IPv6 representations, or expand and compress any IPv6 address. Results update as you type.
Detect overlapping IP address ranges between CIDR blocks. Check a single pair or scan an entire list for conflicts.
Find unallocated gaps in a CIDR block after accounting for allocated subnets.
Calculate DHCP pool range and total leases from a subnet. Exclude reserved IPs and generate a ready-to-paste config.
Calculate the effective MTU and TCP MSS after adding tunnel and encapsulation overhead to your base MTU.
Look up IP addresses, domains, and ASNs: geolocation, WHOIS, reverse IP, MAC vendor, BGP, and RPKI.
Look up domain registration details - registrar, expiry date, nameservers, and status. Data comes from the RDAP protocol, the modern successor to classic WHOIS.
Check how old a domain is and when it expires. Uses WHOIS/RDAP registration data.
Find subdomains by searching public Certificate Transparency logs. Results include all subdomains that have ever had an HTTPS certificate issued.
Look up location, ISP, ASN, timezone, and proxy detection for any IP address.
Look up an Autonomous System Number to see the organisation and all announced IP prefixes. Also resolves any IP address to its ASN.
Check if an IPv4 address is listed on 15 major DNS-based spam and abuse blacklists (DNSBLs).
Find all domains hosted on an IP address using passive DNS data and web crawl records.
Identify the manufacturer of any network device by its MAC address or OUI.
Look up the BGP routing information for any IP address or CIDR prefix. See which AS announces the route, the organisation name, and the parent IP block.
Validate whether a BGP route has a valid Route Origin Authorization (ROA). Detects potential prefix hijacks and misconfigured RPKI records.
Check if a domain name is available across .com, .net, .io, .dev, and .app in one search.
Validate email deliverability: DKIM, DMARC, SMTP, MX health, header analysis, and email security checks.
Enter an email address to validate it and grade its domain security, or enter a domain alone to check SPF, DMARC, DKIM, and MX records.
Verify that a DKIM public key is published correctly for a domain and selector.
Paste raw email headers to trace the delivery path, check authentication results, and measure hop-by-hop timing.
Check if a mail server accepts connections on ports 25, 465, and 587. Also tests STARTTLS and TLS security for all MX servers.
Test SMTP TLS security across all MX servers. Checks STARTTLS advertisement, TLS upgrade success, and MTA-STS policy enforcement. Overall grade A-F.
Check the health of your mail exchange servers. Tests IP resolution, PTR match, SMTP port 25 reachability, and STARTTLS capability for each MX record.
Check MTA-STS transport security policy and BIMI brand indicator record for any domain - both in one lookup.
Build a valid DMARC TXT record for your domain. Choose a policy, add a reporting address, and copy the result into your DNS.
Test live websites and services: SSL, ports, HTTP headers, redirects, CSP, WebSocket, CORS, and SEO audits.
Check if any website is reachable right now. Probed from a Cloudflare edge server and a neutral host, so a site that only blocks Cloudflare is not reported as down.
Check a domain’s SSL certificate - expiry date, issuer, covered domains, and whether HTTPS is currently reachable.
Test a specific port, scan 28 common ports, or check which self-hosted services are exposed on any host or IP address - checked from VLANlab global edge servers.
Check Open Graph tags, Twitter Cards, meta description, favicon, and hreflang for any URL. Preview how your page looks when shared on Facebook, X/Twitter, LinkedIn, and Slack.
Check TLS certificate revocation status via OCSP.
Send real ICMP echo requests from a neutral host to any server. Runs 5 packets and reports min, avg, max, and packet loss.
Inspect response headers and grade the HTTP security configuration for any URL. One request - raw headers and an A‑F security score side by side.
Trace every HTTP redirect hop for any URL - see status codes, final destination, and timing per step.
Analyze Content Security Policy headers from any URL or paste a CSP string directly. Get a security grade, per-directive breakdown, and actionable violation details.
Detect the technologies powering any website - CDN, web server, CMS, framework, and analytics. Detected from HTTP response headers and HTML source.
Trace the network path to any hostname or IP - hop-by-hop latency, packet loss, and geolocation from our VPS in Vienna, Austria.
Check which HTTP protocol version a website uses and whether it advertises HTTP/3 (QUIC) support via the Alt-Svc header.
Parse the robots.txt file for any website - see crawler rules, blocked paths, and sitemap URLs in a readable format.
Paste a PEM-encoded certificate to decode all its fields. Runs entirely in your browser - nothing is sent to a server.
Connect to a TCP port and read the initial service greeting banner.
Connect to any WebSocket endpoint from your browser. Send messages and inspect the full frame log with timestamps.
Fire a real preflight OPTIONS request from a global edge server. See what Access-Control headers the server returns and whether your API allows cross-origin requests.
Measure TTFB and HTTP response time for any URL. Results are measured from Cloudflare’s nearest edge, not your browser.
Validate JSON-LD, schema.org types, Open Graph, and Microdata from any URL or raw input.
Check if a website has a valid Web App Manifest and meets PWA installability requirements.
Audit a page’s core SEO signals: title, meta description, H1, canonical, Open Graph, image alt tags, and heading structure.
Security utilities: password strength, hash generation, one-time secrets, HTTP security scoring, and WebRTC leak detection.
Share a secret that self-destructs after one view. Encrypted in your browser with AES-256-GCM - the server never sees your plaintext.
Generate MD5, SHA-1, SHA-256 and SHA-512 hashes from any text or file. All processing happens in your browser - no data is transmitted.
Check how strong your password is. Your password is never sent to our server - all analysis runs in your browser.
Check if a domain publishes a security.txt file (RFC 9116) with responsible disclosure contact information.
Search Certificate Transparency logs for all SSL/TLS certificates issued for a domain. Detect unauthorized certificates and track your issuance history via crt.sh.
Test if your nameservers allow DNS zone transfers. A server that responds to AXFR queries exposes your full DNS structure including internal hostnames.
Grade any website A+ to F on its HTTP security headers. Checks HTTPS enforcement, HSTS, CSP, X-Frame-Options, and more.
Check if your browser leaks your real IP address through WebRTC, even when using a VPN or proxy. Runs entirely in your browser - no data leaves your device.
Check the abuse reputation score of any IP address. Powered by AbuseIPDB.
Developer utilities: JSON/YAML, Base64, JWT, regex, timestamps, cron, UUID, and base conversion.
Paste JSON to format, minify, or validate it instantly. All processing happens in your browser - no data is transmitted.
Paste YAML to format, validate, minify, or convert to and from JSON. All processing happens in your browser - no data is transmitted.
Encode or decode Base64 and URL percent-encoded strings. Supports Unicode. Runs entirely in your browser.
Paste a JWT token to decode its header and payload claims. Runs entirely in your browser - the token is never sent to a server.
Test regular expressions with real-time match highlighting, flag toggles, match details and replace mode. All processing runs in your browser.
Convert between Unix epoch timestamps and human-readable dates. Live counter, seconds and milliseconds both supported.
Pick a schedule from the presets below, or paste any cron expression to see it explained in plain English with the next 5 run times.
Generate universally unique identifiers in your browser. UUID v4, UUID v1, and ULID - no server, no tracking.
Convert between Unicode international domain names and Punycode (ACE) encoding used in DNS.
Convert numbers between binary, octal, decimal, hexadecimal, and any base from 2 to 36. Shows two's complement at 8, 16, 32, and 64 bits.
Build Cisco IOS and iptables access control rules visually. Add permit/deny entries and copy the ready-to-paste config.
Web and frontend tools: color conversion, CSS units, gradients, URL encoding, HTTP status codes, and cURL builder.
Convert between all 14 CSS units instantly. Enter px, rem, em, vw, vh, pt, cm, in, or any other unit and see all conversions at once with context-aware relative unit support.
Convert colors between HEX, RGB, HSL, HSV, and CMYK. Check WCAG contrast ratios, generate color palettes with harmony rules, and create tint and shade scales.
Build CSS gradients visually. Configure color stops, opacity, and positions for linear, radial, and conic gradients and copy the ready-to-use CSS.
Build HTTP request code from a visual form. Fill in the URL, method, headers, auth and body - get curl, fetch, axios or Python snippets ready to paste.
Break any URL into its components - protocol, hostname, path, port, query parameters and fragment. Runs entirely in your browser.
Encode or decode URL percent-encoded strings. Choose the mode that matches your use case - full URL, query string, or single component.
Look up any HTTP status code or check the live status of a URL.
Build CSS box shadows visually with live preview. Control offset, blur, spread, color, and multiple layers. Copy ready-to-use CSS instantly.
Generate all favicon sizes from any image. Produces ICO, PNG (16, 32, 48, 180, 192, 512px), HTML tags, and a ZIP download. No server upload.
Build CSS Flexbox and Grid layouts visually with live preview. Control container and item properties, then copy the ready-to-use CSS.
Test robots.txt rules before deploying. Paste your robots.txt and a URL path to see if crawlers are allowed or blocked, with the exact matching rule shown.
Text manipulation: case conversion, diff, cleaning, analysis, lorem ipsum, slug generation, and list tools.
Paste two texts to compare them line by line. Changed words are highlighted within each line.
Convert text to UPPERCASE, lowercase, camelCase, snake_case, kebab-case, Title Case, and more. All 11 cases shown instantly. Runs in your browser.
Clean up messy text instantly. Remove extra spaces, blank lines, HTML tags, and special characters. Paste from Word or PDF, get clean plain text.
Count words, characters, sentences, and paragraphs. Get reading time, speaking time, top words, and readability scores including Flesch-Kincaid, Gunning Fog, and SMOG. Runs in your browser.
Encode and decode text with Base64, URL encoding, HTML entities, hex, ROT13, Morse code, and binary. Instant, no signup, runs in your browser.
Sort, deduplicate, shuffle, number, filter, and join lines in any list. Paste your list, pick an operation, get clean output instantly.
Generate Lorem Ipsum placeholder text by paragraphs, sentences, or words. Instant, no signup, runs in your browser.
Convert any text to a URL slug, filename, hashtag, or handle. Strips accents, removes special characters. Instant, runs in your browser.
Cloud infrastructure tools: VPC planning, IP ranges, security groups, IAM, Kubernetes CIDR, HCL, and egress costs.
Plan your cloud network layout for AWS, Azure, or GCP. Define subnets, get provider-aware usable host counts, and generate ready-to-run CLI commands and Terraform HCL.
Check whether an IP address belongs to AWS, GCP, or Cloudflare by matching against each provider's official published prefix lists.
Paste an AWS Security Group or Azure NSG JSON to flag overly permissive rules. Detects critical exposures like SSH, RDP, and database ports open to the internet.
Paste an AWS IAM policy, Azure RBAC role definition, or GCP IAM policy JSON to instantly flag dangerous permissions and overpermissive patterns.
Plan Kubernetes pod CIDR, service CIDR, and node ranges for EKS, AKS, and GKE. Avoid overlap conflicts before cluster creation with instant validation and kubeadm output.
Build AWS Security Group and Azure NSG firewall rules visually. Add SSH, HTTPS, RDP presets or custom ports. Get CLI, Terraform, and JSON output instantly.
Format and beautify Terraform HCL code instantly. Aligns equals signs, fixes indentation, and normalizes whitespace - same output as terraform fmt. No install needed.
Estimate AWS, Azure, and GCP data transfer costs. Compare egress pricing across tiers, regions, and transfer types with a live side-by-side breakdown.
Generate Route 53, Azure DNS, and GCP Cloud DNS zone configs from your DNS records as CLI commands or Terraform HCL.
Config generators for Proxmox, VMware, Hyper-V, KVM, XCP-ng, and NSX-T: network bridges, VLANs, and VXLAN.
Generate paste-ready /etc/network/interfaces entries for Proxmox bridges, bonds, VLANs, and OVS bridges.
Generate esxcli, PowerCLI, and Terraform commands to create vSphere standard or distributed switch port groups.
Generate PowerShell commands to create Hyper-V external, internal, or private virtual switches, with optional VLAN tagging.
Allocate VNI ranges across segments and generate multicast group assignments. Get Linux VTEP, Open vSwitch, and Cisco NXOS deployment commands.
Generate libvirt network XML definitions for KVM virtual machines. NAT, bridged, isolated, and macvtap network types with virsh commands and optional netplan bridge config.
Generate xe CLI commands for XCP-ng VLAN networks and NIC bonds as a ready-to-run shell script.
Generate NSX-T logical segment API payloads for overlay and VLAN transport zones with curl and Policy API JSON output.
Open-source intelligence tools: validate phone numbers, detect disposable emails, check Tor exits, and flag proxies.
Check any email address against 10,000+ known disposable email providers. Validates syntax and MX records instantly.
Validate any phone number and see country, type, location, and all format variants. Client-side lookup covering 230+ countries, no data sent.
Check if an IP address is a known Tor exit node using the Tor Project's official public exit list.
Check any IP address to detect VPN, proxy, datacenter, or residential connection type.
Check if a domain has been flagged as malware or phishing by URLhaus and OpenPhish threat feeds.
Find registered typosquatting variants of any domain using keyboard swaps, homoglyphs, TLD swaps, and more.
Check if a username is available on GitHub, Instagram, TikTok, Reddit, Twitch, and 30+ more platforms instantly.
Generate the Shodan MurmurHash3 favicon hash for any URL. Use the result in Shodan's http.favicon.hash filter to find servers running the same software.
CI/CD and container config generators: GitHub Actions workflows, Dockerfiles, docker-compose, ArgoCD, and Kubernetes manifests.
Generate GitHub Actions workflow YAML for any language. Pick your triggers, OS, and steps.
Generate production-ready Dockerfiles for Node.js, Python, Go, Java, and Nginx with multi-stage builds and optimized layer ordering.
Generate docker-compose.yml files for multi-service applications with services, volumes, networks, and environment variables.
Generate ArgoCD Application manifests for GitOps deployments with sync policies, auto-heal, and Helm support.
Generate Kubernetes YAML manifests for Deployments, Services, ConfigMaps, Ingress rules, and HPAs.