Mail auth, TLS cert, and headers.
What this measuresThree sightings. One position.
Site security, agent readiness, skill supply chain - one reading.
Free, no signup. Your report is a shareable link.
Can an agent use this site.
What this measuresNot built in the engine yet.
What this will coverWhat a domain says about itself
DNS and transport posture: SPF, DMARC, DKIM, CAA, DNSSEC, TLS, security headers and cookies. Read on every scan and reported as evidence, with no score attached until a grading threshold has been measured.
PUBLIC DNS
ONE CONCURRENT BLOCK- SPFno v=spf1 recordTXT northharbour.
example warnNo SPF recordTXT northharbour.example -> no v=spf1 recordemail. spf. absent - DMARCp=noneTXT _
dmarc. northharbour. example warnDMARC is monitor only (p=none)v=DMARC1; p=none; rua=mailto:dmarc@northharbour.exampleemail. dmarc. monitor_ only - ISSUANCENODATACAA northharbour.
example warnNo CAA recordCAA northharbour.example -> NODATAtls. caa. absent - MTA-STSNODATATXT _
mta-sts. northharbour. example warnNo MTA-STS policy announcedTXT _mta-sts. northharbour. example -> NODATAemail. mta_ sts. absent - TLS-RPTNODATATXT _
smtp. _ tls. northharbour. example warnNo TLS reporting addressTXT _smtp. _ tls. northharbour. example -> NODATAemail. tls_ rpt. absent - DKIMnothing at the common selectorsTXT <selector>.
_ domainkey. northharbour. example19 selectors, under a concurrency cap warnDKIM: no DKIM key found at common selectorsselectors tried: default, google, selector1, selector2, k1 .. .email. dkim. not_ found_ at_ common_ selectors - DNSSECsignature validatesDNSKEY via DoHisolated: its own timeout, its own failure pathokDNSSEC signed and validatingDNSKEY present, signature validatesdns.
dnssec. signed
ready
next
Collected on every scan and reported as evidence. No score, no letter, and no total - the engine publishes no count of these, and a number arrived at any other way would not be one it computed.
WHAT SECURITY READSWhat an agent actually receives
What an AI shopping agent can find, parse and trust: discovery files, crawler access, product schema, merchant data and content depth. Every failing check ships with the fix written out.
Harbour Shell Jacket
4.8(127 reviews)
$289.00
In stock, ships today
A three-layer waterproof shell cut for coastal weather: 20k/20k rated fabric, fully taped seams, and a two-way front zip under a storm flap. The hood adjusts with one hand and stows flat when the rain stops.
Pit zips run long for fast venting, the hem cinches over a mid layer, and both hand pockets sit above pack-strap height. Weighs 410 g in a men's medium. Cut is regular; size up for winter layers.
JSON-LD, as served
{
"@context": "https://schema.org",
"@type": "Product",
"name": "Harbour Shell Jacket",
"sku": "",
"image": "cdn/img/hs-1.jpg",
"description": "A great addition to
your daily wardrobe.",
"offers": {
"@type": "Offer",
"price": "289.00",
"priceCurrency": "USD"
}
}Extracted text
A great addition to your daily wardrobe.- 40 characters
Not in the payload
- Fail
sku: empty string - Fail
gtin13: absent - Fail
aggregateRating: absent - Fail
availability: absent - Warning
image: 1 of 6
What a person sees at northline.example/products/harbour-shell: Harbour Shell Jacket, $289.00, rated 4.8 from 127 reviews, in stock, ships today, sizes XS, S, M, L, XL available. A three-layer waterproof shell cut for coastal weather: 20k/20k rated fabric, fully taped seams, and a two-way front zip under a storm flap. The hood adjusts with one hand and stows flat when the rain stops. Pit zips run long for fast venting, the hem cinches over a mid layer, and both hand pockets sit above pack-strap height. Weighs 410 g in a men's medium. Cut is regular; size up for winter layers.
What an agent gets, as the JSON-LD actually served: { "@context": "https://schema.org", "@type": "Product", "name": "Harbour Shell Jacket", "sku": "", "image": "cdn/img/hs-1.jpg", "description": "A great addition to your daily wardrobe.", "offers": { "@type": "Offer", "price": "289.00", "priceCurrency": "USD" } }
The text extracted from that same payload instead of the page copy: "A great addition to your daily wardrobe." - 40 characters.
Not in the payload: sku (empty string); gtin13 (absent); aggregateRating (absent); availability (absent); image (1 of 6).
An agent reading this page cannot say which jacket this is, whether it is in stock, or whether anyone has ever rated it. The person can see all three without trying.
What changed after you looked
Which third-party skills, plugins and MCP servers a site declares, and where they come from. In development - it reports as not measured rather than as a pass.
Nothing in the engine implements this family. There is no module, no check and no finding behind it, so a scan returns no reading for it - not a low one, and not a failing one.
- reads the page it is invoked on
- no network egress declaredadded: posts to an endpoint not named in the manifest
- no filesystem paths declaredadded: reads a credentials path outside its own directory
A version that was safe when it was reviewed is not evidence about the version running now. That gap is what this family would be for, and it is why it would have to watch rather than scan once.
WHY IT REPORTS NOT MEASUREDWhy it costs nothing
A scan reads what your site already returns to the public. It costs us a few seconds of bandwidth, so charging for it would be charging for arithmetic. The paid tiers are for the things that genuinely cost something to run: scheduled re-scans, score history, and alerts when a check regresses.
Scanning is passive. We read public responses and public DNS - no path guessing, no port scanning, no attempt to authenticate. A report is evidence of what we could see at one moment, never a certificate that a site is secure or compliant.
Before you scan
The questions people actually ask, answered plainly.
- What does 'agent readiness' mean?
- Whether an AI shopping agent can find your store, read your products as structured data rather than prose, and trust your returns and shipping terms enough to recommend you. It is not a score you can talk your way into. Either the crawler is let in and the schema is there, or it is not.
- What does the scan actually check?
- 30 checks across five categories: discovery files such as llms.txt and agents.md, whether AI crawlers are allowed in by robots.txt, product structured data, machine readable returns and shipping, and content depth. Every check comes back with the evidence we found and the fix, not just a number.
- Does the scan change anything on my store?
- No. It only reads what is already public: your homepage, robots.txt, sitemap, a sample of product pages and your policy pages. Nothing is installed, no account is created, and nothing on your store is written to.
- What does it cost to fix what the scan finds?
- The scan and its fixes are free to read and free to implement yourself. If you would rather we did it, done for you implementation is $800 flat for Shopify and WooCommerce stores up to 50 products. Larger catalogs and other platforms quoted before we start. You can book and pay for it in one step, no account needed.
- What if my store is bigger than 50 products?
- Then it is quoted rather than flat, and the quote is fixed and agreed before any work starts. Tell us the platform and roughly how many products you have and we will price it. If you have already booked at $800 and the store turns out to be over scope, we agree the difference with you or refund you in full, before we touch anything.
- How long does a scan take?
- Usually 15 to 30 seconds. We fetch your homepage, six discovery files, your sitemap and up to 5 product pages, three requests in flight at a time so we are not hammering your server.
The directory
Every domain that has been scanned and made public, with its reading and its history. Nothing is listed that was not scanned, and a reading shows grades only.
BROWSE THE DIRECTORY