Keywatch

Know your external crypto surface before it breaks.

Keywatch scans your TLS endpoints, certificates, DNSSEC, email authentication and OIDC/JWKS from the outside — grades your post-quantum readiness, and alerts you before a cert expires, an SPF record breaks, or auth goes down at 3am.

Free instant grade. No signup. Shareable report.

Scanning…

TLS / PQC

RSA/ECC inventory, hybrid X25519+ML-KEM support, expiry & chain health.

Email auth

SPF 10-lookup breaches, weak DKIM keys, DMARC policy drift, BIMI/VMC.

DNSSEC

Signature expiry, DS/DNSKEY mismatch, rollover sanity — before you go dark.

OIDC / JWKS

Stale keys, dead endpoints, issuer cert expiry — before everyone gets logged out.

PKI & signatures

Inspect & monitor your external PKI surface, and dissect signatures structures — signer chain, timestamps, eIDAS status.

CT / certs

Full certificate inventory from the public logs, plus mis-issuance: a CA you don't use issuing for you.

Brand impersonation

Look-alike domains across CT, DNS permutations & phishing feeds — flagged the day they're registered.