Inspector
Paste anything: MAC, IP, CIDR, domain, URL, email, JWT, certificate, hash, timestamp or base64. See what it is and where to take it next.
55 tools in 7 families, 26 available today. The rest are listed so you can see what is coming and where it will live.
This catalogue submits anonymous tool-use counts kept in your browser. It sends no pasted text or result. How the counts work.
Paste anything and find out what it is, then jump to the right tool.
Strict parsing, bit semantics, IEEE assignments and bulk annotation for hardware addresses.
One address, deep: strict format parsing, U/L and I/G bits, randomized address detection, IEEE block and registrant, EUI-64 and IPv6 link-local.
Paste ARP tables, switch output, DHCP leases or CSV; every address is extracted, annotated with its registrant and block type, and exported as CSV or JSON.
Random addresses with your choice of count, separator, case, U/L and I/G bits or a registered prefix; bit conflicts are reported, not rewritten.
Colon, hyphen, Cisco dotted, bare, EUI-64, bit-reversed and IPv6 link-local forms of one address.
Versioned IEEE assignment snapshot downloads in JSON and CSV with provenance, dates and SHA-256 checksums.
Find every block assigned to an organization by substring.
Subnet math, CIDR operations, address classification and network enrichment.
IPv4 or IPv6, detected as you type: live bit map, netmask, wildcard, first and last address, and what /31 and /32 really mean.
Split, aggregate, contains, exclude, range to CIDR and CIDR to range.
VLSM allocation from a parent block and a list of sizes, a visual split tree, IPv6 nibble plans and exports for Terraform and routers.
Classification against the special-use registries, normalization, integer and binary forms, PTR name and mapped forms; enrichment on request.
Your public address as our edge sees it, with rDNS, ASN, country, request headers and client hints.
ASN and prefix, RPKI validity, attributed geolocation, abuse contact and rDNS for any address.
An autonomous system at a glance: name, prefixes, peers, RPKI status and PeeringDB presence.
An address against a curated set of public blocklists, with listing evidence and delist links.
Is a common port open on your own public address, seen from our vantage point. Arbitrary targets are not offered.
ICMP and TCP reachability and an MTR-style path from the app host, labelled as one vantage point.
Resolution, registration data, email authentication and certificate transparency.
Any record type from your choice of resolver, with DNSSEC flags, TTLs, distinct outcomes and every answer clickable.
The same query against several public resolvers side by side, from one vantage point.
Registration data for domains, IPs and ASNs via RDAP with WHOIS fallback; expiry, nameservers, registrar and status codes explained.
SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI, MX, DANE and DNSSEC for a domain, with generated fix records and a graded scorecard.
Open a DMARC aggregate XML, .gz or .zip and read it as a table, in your browser.
Issued certificates for a domain: issuers, SANs, first and last seen, and the subdomains they reveal.
Zone sanity: NS consistency, SOA serials, lame delegation, open resolvers, glue, CAA and DNSSEC chain.
Redirect chains, security headers, TLS configuration and certificate handling.
Redirect chain with status and location per hop, final headers, timings, HTTP version, compression and cookie flags.
Grade and per-test findings from the MDN HTTP Observatory engine, with plain-language fixes and server snippets.
Certificate, chain, expiry, protocols, key size and common misconfigurations in a few seconds.
A complete testssl.sh run on an isolated scan host: protocols, ciphers, vulnerabilities, grade and downloadable evidence, with live progress.
Paste PEM, DER, CSR or PKCS#7: subject, SANs, key, signature, extensions, validity and fingerprints, decoded in your browser.
PEM, DER, PKCS#7 and PKCS#12 conversions without the key leaving your browser.
Generate a key and certificate signing request locally, with the equivalent OpenSSL config shown.
Encoders, hashes, tokens, timestamps and text tools that run entirely in your browser.
Validate, format, minify, sort keys, query with JSONPath and convert to or from YAML, TOML and CSV.
UTF-8 Base64 and hex, URL components and parsing, HTML entities, IDN-to-ASCII and quoted-printable byte escapes.
WebCrypto SHA-1 and SHA-2 digests over text or local files, plus HMAC with a text key.
Decode header and payload locally, explain time claims and clearly mark the signature as unverified.
Unix seconds and milliseconds, timezone-qualified ISO 8601 and RFC 2822, UTC forms and relative time.
Generate UUID v1, v4, v5 and v7, ULID and Nano IDs; inspect UUID versions and embedded timestamps.
Passwords and diceware passphrases from WebCrypto, with random selection estimates and WPA PSK derivation.
Match highlighting, groups, replace and flags, run in a worker with a timeout.
Parse a cron expression to English, list the next runs in a chosen timezone, or build one.
Text and JSON diff, side by side or unified, with whitespace ignored on request.
Generate QR codes for text, Wi-Fi and vCards, and scan one from your camera or an image.
Exact binary, octal, decimal and hex conversion, IP address to integer and back, and dotted IPv4 masks.
File permission calculator, symbolic and octal.
Format, validate and convert YAML.
Format, validate and convert XML.
Format, validate and convert CSV.
Preview Markdown and export the HTML.
HEX, RGB, HSL and OKLCH conversion with a contrast checker.
DNS record types, HTTP status codes, common ports, MIME types, ASCII, subnet cheat sheet and special-use ranges.
What your own browser and connection reveal, explained honestly.
User agent, client hints, screen, languages, timezone and WebGL renderer: what a site can and cannot see.
ICE candidate gathering with an honest explanation of mDNS obfuscation.
Bandwidth and latency measured against the Cloudflare edge using its open measurement engine.
The JA4 fingerprint and cipher suites your own browser offers when it connects.