Know your external crypto surface before it breaks.
Keywatch scans your TLS endpoints, certificates, DNSSEC, email authentication and OIDC/JWKS from the outside — grades your post-quantum readiness, and alerts you before a cert expires, an SPF record breaks, or auth goes down at 3am.
Free instant grade. No signup. Shareable report.
TLS / PQC
RSA/ECC inventory, hybrid X25519+ML-KEM support, expiry & chain health.
Email auth
SPF 10-lookup breaches, weak DKIM keys, DMARC policy drift, BIMI/VMC.
DNSSEC
Signature expiry, DS/DNSKEY mismatch, rollover sanity — before you go dark.
OIDC / JWKS
Stale keys, dead endpoints, issuer cert expiry — before everyone gets logged out.
PKI & signatures
Inspect & monitor your external PKI surface, and dissect signatures structures — signer chain, timestamps, eIDAS status.
CT / certs
Full certificate inventory from the public logs, plus mis-issuance: a CA you don't use issuing for you.
Brand impersonation
Look-alike domains across CT, DNS permutations & phishing feeds — flagged the day they're registered.