d4 · network tools
Small, sharp network tools. No sign-up, no adverts, no tracking. Where a tool runs in your browser, nothing you type ever reaches our server; where it runs on our server, we say so and we keep nothing.
Which vulnerabilities are actually being exploited: CISA's KEV catalogue with CVSS and EPSS on demand, plus vendor RSS feeds.
Runs on our serverThe MITRE ATT&CK Enterprise matrix of adversary tactics and techniques, with overlays showing how a given CVE is used in real intrusions.
Runs on our serverIPv4 and IPv6 subnetting: ranges, masks, splitting, VLSM planning, aggregation and overlap checks.
Runs in your browserQuery any record type against four public resolvers at once and race their response times.
Runs in your browserSPF, DKIM, DMARC, MTA-STS and TLS-RPT for any domain, graded in plain English.
Runs in your browserFetch any site's response headers and grade HSTS, CSP, frame protection and more.
Runs on our serverScan any page for hidden trackers: advertising pixels, session recorders, fingerprinters, and exactly which companies receive your data.
Runs on our serverExpiry countdown, subject alternative names, issuer chain, key strength and negotiated protocol.
Runs on our serverYour IP address, reverse DNS, network owner and exactly what your browser sends with every request.
Runs on our serverBuild a Content-Security-Policy from sensible defaults, or paste one and have every directive checked and explained.
Runs in your browserPaste a message's raw headers to trace its delivery path, hop delays and SPF, DKIM and DMARC results.
Runs in your browserDecode a JSON Web Token's header and claims, with expiry and algorithm checks. It decodes only, it never verifies or stores.
Runs in your browserPaste a PEM certificate or CSR to read its subject, validity, key and subject alternative names, entirely on your machine.
Runs in your browserGenerate strong diceware passphrases and random passwords with honest entropy, using your browser's secure randomness.
Runs in your browserSee whether a password appears in known breach data. Only the first five characters of its hash are sent, so the password never leaves your device.
Runs in your browserSHA hashes, Base64, URL, hex and HTML encoding, and Subresource Integrity attributes, all computed locally.
Runs in your browserCheck a domain's security.txt against RFC 9116: contact, expiry, canonical location and whether it is signed.
Runs on our serverSee whether a domain publishes DNSSEC signing and CAA records, plus its nameservers, SOA and MX.
Runs on our serverBrowser-based tools talk directly to public DNS-over-HTTPS resolvers (Cloudflare, Google, DNS.SB, AliDNS) from your machine. Server-based tools are rate limited, only ever connect to publicly routable addresses, and store nothing about what you look up.