Security tools

Thirteen small tools we use ourselves and have opened to everyone. No sign-up, no tracking. Files and passwords are processed in your browser and never uploaded; links and addresses are checked against open threat data.

Before you click or pay

For everyone. Most fraud starts with a link, a QR code or an attachment.

  1. Link checkerPaste a link from an SMS, WhatsApp or email. We pick the address apart, follow the redirects from our server, and check it against URLhaus and the domain's registration date.since 1 Oct 2026
  2. QR code checkerUpload a photo of a QR code (parking, payment, poster). We decode it on your device and run the link through the link checker.since 2 Oct 2026
  3. UPI payment-link checkerPaste a upi:// link or a UPI ID. We check the handle, the amount, the note text and whether it is a collect request — the kind that empties accounts.since 2 Oct 2026
  4. Attachment checkerDrop an email attachment. It is read on your device only: real file type, hidden macros, scripts in PDFs, programs inside ZIPs. Only the hash is looked up.since 1 Oct 2026
  5. Email header analyserPaste the headers of a suspicious email to see who really sent it, where replies go, and whether SPF, DKIM and DMARC passed.since 1 Oct 2026

Your accounts and privacy

Passwords, breaches and what your connection reveals.

  1. Email breach exposureFind out which known data breaches contained your email address, what was leaked, and what to change first.since 2 Oct 2026
  2. Password checker and generatorStrength estimate, a privacy-preserving check against leaked passwords, and a passphrase generator.since 1 Oct 2026
  3. What does the internet see?Your public IP, network, location and browser details, plus a WebRTC leak test — useful when you are on a VPN or public Wi-Fi.since 2 Oct 2026

For IT teams and institutions

Checks we run during engagements, made self-service.

  1. Domain security checkFor IT teams: SPF, DKIM, DMARC, DNSSEC, CAA, HTTPS redirect, security headers, security.txt and recently issued certificates for your institution's domain.since 2 Oct 2026
  2. IP address checkerOwner, reverse DNS and whether an address appears on botnet, criminal-network or Tor lists. For login alerts and firewall logs.since 1 Oct 2026
  3. Download integrity verifierCompute SHA-256, SHA-1, SHA-512 and MD5 of a downloaded file in your browser and compare with the hash the vendor published.since 2 Oct 2026
  4. Institution self-assessmentTwenty questions across five domains, scored as you go, with an emailed report.since 1 Oct 2026

For analysts and students

Small utilities we kept rewriting, so we published them.

  1. Decoder and IOC extractorBase64, URL-encoding, hex, ROT13 and HTML entities; defang/refang; pull URLs, IPs, emails and hashes out of a pasted email or log.since 2 Oct 2026

Why we built these

Every week someone in our network — a student, a parent, an administrator at a college we work with — forwards us a message and asks “is this real?”. Usually it takes us two minutes and the same handful of checks. These pages are those checks, written down and automated, so you can run them yourself at 11 pm without waiting for a reply.

They are deliberately simple. A tool here will tell you what it found and why it matters; it will not pretend to certainty it does not have. When a check says “no red flags”, read it as “nothing we test for”, not “safe”.

How they work, briefly

  • Nothing you upload is stored. Attachments and passwords never leave your device. For breach checks we send the first five characters of a hash, not the password.
  • Threat data is open. abuse.ch (URLhaus, MalwareBazaar, Feodo Tracker), Spamhaus DROP, the Tor exit list, RDAP and Have I Been Pwned. We credit each source on the result.
  • We fetch links from our server, never from your browser, so a malicious site does not see you.
  • Rate limits apply (40 checks per network per 10 minutes) so the tools stay available to everyone.
  • Open source. The code is on GitHub under the MIT licence. Fixes and ideas welcome.

Changes

2 Oct 2026
Added QR, UPI, breach exposure, domain check, download verifier, decoder and “what does the internet see”. Passphrase generator on the password page. Tools moved to the main menu.
1 Oct 2026
First release: link, attachment, IP, password and email-header checkers.

Known limits: the breach-exposure search needs an API key we are still arranging; VirusTotal and AbuseIPDB rows show “Not enabled” until keys are added; the QR decoder needs a reasonably sharp photo.

Built and maintained by the Arventiq Labs team in Bengaluru. Free for anyone, source on GitHub (MIT). Results are indications, not verdicts. Something wrong? Tell us.