Automated checks · web · api · mail · mobile links

Find out where your product breaks before your users do.

Recon Node checks your site the way a browser, a crawler, a mail server and a phone each would — around thirty checks across TLS, headers, links, DNS, mail and app deep links — and hands you a plain list of what is wrong, with the evidence it saw.

Get early access Run a live check No signup needed to try it
Run RN-0417 · full sweep scanning
Mobile links / android · ios
Web & API / http · tls · headers
Mail & DNS / spf · dmarc · dnssec

01 · What you can point it at

Everything reachable from a URL.

Paste an address and try it — no signup for the first run. Recon Node checks what a browser, a crawler, a mail server and a phone each see when they arrive, and keeps the history so you can tell what changed.

Mobile deep linksLive now

The two files that decide whether a link opens your app or dumps the user in a browser. They fail silently: nothing errors, the app just looks like it was never installed.

  • Android App Links — assetlinks.json
  • iOS Universal Links — apple-app-site-association
  • Redirects and wrong content types, which break both
  • Certificate fingerprints and team IDs
  • Viewport, zoom blocking and web manifest

Web and API surfaceLive now

Give it a URL. It follows the redirects, reads what the server volunteers, walks the internal links and reports the things a browser would hit that you would not.

  • Status codes, error handling and response time
  • TLS chain, certificate expiry and HSTS
  • Security headers, CSP, cookies and CORS
  • Broken links, exposed files and source maps
  • Third-party scripts and missing SRI

Mail and DNSLive now

The half of your domain that has nothing to do with the website, and that nobody looks at until someone spoofs it.

  • SPF and DMARC, including whether it is enforced
  • MTA-STS and mail transport policy
  • DNSSEC, CAA and IPv6
  • Certificate Transparency and live subdomains
  • Subdomain takeover exposure

02 · How a run works

Point it, leave it, read the report.

STEP 01 — DISPATCH

You give it a URL

Standard for a quick pass, deep for the full sweep including TLS, DNS, mail and subdomains. No agent to install, nothing to add to your site, and the first run needs no account.

STEP 02 — SWEEP

It looks from the outside, like anyone else

Requests go out from Cloudflare's edge, not from your machine, so what it sees is what the public sees. Every finding carries the header, record or response that produced it.

STEP 03 — REPORT

You get findings, not a wall of logs

Findings are grouped, deduplicated against previous runs and marked new, still open or fixed. Repeat noise stops appearing after the second run.

03 · Monitoring

It keeps watching after you close the tab.

EVERY 15 MINUTES

Three sites, checked around the clock

Add up to three sites to your account and Recon Node checks each one every fifteen minutes from outside your infrastructure. Free, with no card and no trial period.

EMAIL ALERTS

Told once when it breaks, once when it returns

An email when a site goes down and another when it comes back. Alerts fire on the second consecutive failure, so a single blip stays quiet, and never repeat during the same outage.

CHANGE DETECTION

And when the site changes underneath you

Recon Node fingerprints your security headers and third-party scripts. If a new tracking script appears or your Content-Security-Policy weakens, you hear about it — which is the part uptime tools do not watch.

STATUS PAGES

A public page you can share

Turn any monitor into a public status page showing uptime, incidents and response time. Sharing is off until you switch it on.

04 · What a report looks like

Every finding says what it saw.

Run RN-0417 Target example.com Duration 3.3s Findings 6 open · 2 fixed
Critical Session cookie is set without the Secure flagSent in clear text on any downgraded request Set-Cookie · sid
Critical apple-app-site-association returns HTMLEvery iOS universal link opens Safari instead of the app content-type: text/html
Major No HSTS headerA first visit can be downgraded to http before the redirect strict-transport-security missing
Major Third-party script loads without SRIIf that origin is compromised, it runs on your page cdn.example-analytics.com
Major Missing pages return 200 instead of 404Search engines index pages that do not exist /recon-node-probe-qaztppmt
Minor DMARC is published but not enforcedp=none tells receivers to deliver spoofed mail anyway _dmarc TXT

05 · What's coming

Free while we build. Paid tiers arrive with the paid features.

Recon Node is free to use right now — every check, the deep security scan, the surface map, finding history, monitoring and shareable reports. Pricing arrives when there is something worth charging for, and it will be for volume and team features rather than for locking away checks you already use. Until then, use everything, and tell us what's missing.

Live now

Web, mail & mobile links

Status, TLS, headers, cookies, links, meta, DNS, SPF and DMARC, deep links, surface map, finding history. All free.

In build

Continuous

Watching third-party scripts for change, not just for arrival, so a script that is quietly rewritten does not pass unnoticed.

On the roadmap

App binaries

Static analysis of an uploaded APK. Needs machines this runs nowhere near today, so it is honestly some way off.