---
title: Free tools
description: 60 free public tools for one-off DNS, network, web, SSL/TLS, email and performance checks — no account needed — and which monitor type each one turns into.
canonical: https://watchfor.io/docs/tools
---

# Free tools

60 free public tools for one-off DNS, network, web, SSL/TLS, email and performance checks — no account needed — and which monitor type each one turns into.

Alongside continuous monitoring, WatchFor offers a toolbox of **60 free public
tools** for quick, one-off checks — no sign-up required. Use them to diagnose
something right now, or to try a check before turning it into a monitor. The
same toolbox is available inside the dashboard under **Toolbox**, where runs
use your plan's higher limits.

Browse them all on the [free tools hub](/free-tools).

## How they work

- Checks that need a network vantage point (ping, traceroute, port, DNS, SSL,
  HTTP…) run from a real WatchFor [probe location](/docs/reference/probe-locations)
  — the same fleet that runs your monitors — normally the one nearest to you.
  On paid plans you can pick the location. DNS propagation fans out to every
  region at once.
- **Calculators** run entirely in your browser; nothing is uploaded.
- **Limits** are per tool, with a combined cap for anonymous use. Signing in
  gives you your plan's limits, which are higher — see [pricing](/pricing).
  That per-tool plan allowance is **shared with the API**: the 22
  fleet-backed tools are also [live diagnostics](/docs/api/diagnostics) over
  REST, MCP and A2A, and a run there spends the same slot as a run here.
- Several tools also have **focused landing pages** — one record type, one
  question — that run the same engine with a preset: the DNS record lookups
  (A, AAAA, CNAME, MX, NS, TXT, SOA, SRV, CAA, reverse/PTR), SSL expiry,
  TLS versions, security headers, HSTS, HTTP status, domain expiry, sitemap
  validation, gzip, and the crontab / epoch / CIDR / SLA calculators. They
  share their parent's allowance and are listed under it in the hub.
- Most tools produce a **shareable link** that re-runs the check with the same
  input, and some offer a downloadable map or image of the result.

## All-in-one

| Tool | What it does | Continuous version |
| --- | --- | --- |
| [Smart Website Checker](/smart-website-audit) | A combined audit of a site — uptime, performance, security, reputation and configuration in one run, ending in a letter grade ([rubric](/docs/reference/audit-grade)). | Several [monitor types](/docs/monitors) |

## Performance

| Tool | What it does | Continuous version |
| --- | --- | --- |
| [Core Web Vitals Checker](/core-web-vitals-checker) | Real-browser Core Web Vitals (LCP, CLS, TBT) and a Lighthouse-style score. | [Core Web Vitals monitor](/docs/monitors/performance#core-web-vitals-browser) |

## DNS

| Tool | What it does | Continuous version |
| --- | --- | --- |
| [DNS Lookup](/dns-checker) | Resolve a name and inspect its records, against any resolver. | [DNS monitor](/docs/monitors/network#dns) |
| [DNS Propagation](/dns-propagation-checker) | How a record has propagated across resolvers worldwide, on a map. | [DNS monitor](/docs/monitors/network#dns) |
| [Whois Lookup](/whois-lookup) | Registration, registrar and expiry details for a domain (RDAP). | [Domain expiry monitor](/docs/monitors/certificates#domain-expiry) |
| [Domain Expiry Checker](/domain-expiry-checker) | Days until a domain expires, straight from the registry, with the status flags that say whether it can still be renewed. | [Domain expiry monitor](/docs/monitors/certificates#domain-expiry) |
| Record lookups: [A](/a-record-lookup) · [AAAA](/aaaa-record-lookup) · [CNAME](/cname-lookup) · [MX](/mx-lookup) · [NS](/ns-lookup) · [TXT](/txt-record-lookup) · [SOA](/soa-record-lookup) · [SRV](/srv-record-lookup) · [CAA](/caa-record-lookup) · [Reverse DNS](/reverse-dns-lookup) | The DNS Lookup engine opened on one record type, with a page about that record. | [DNS monitor](/docs/monitors/network#dns) |

## Network

| Tool | What it does | Continuous version |
| --- | --- | --- |
| [Ping](/ping-test) | Reachability and round-trip time to a host. | [Ping monitor](/docs/monitors/network#ping-icmp) |
| [Traceroute](/traceroute-online) | The hop-by-hop path packets take, with per-hop latency and loss. | [Network path (MTR) monitor](/docs/monitors/network#network-path-mtr) |
| [Port Checker](/port-checker) | Whether a TCP port is open and accepting connections. | [TCP monitor](/docs/monitors/network#tcp) |
| [Blacklist Check](/blacklist-checker) | Whether an IP or domain is on common DNS blocklists (RBLs). | [Blacklist monitor](/docs/monitors/security#blacklist-rbl) |
| [What Is My IP](/whats-my-ip) | Your public IPv4 and IPv6, geolocation, ASN and reverse DNS. | — |
| [IP Address Lookup](/ip-lookup) | Any IP's ASN and network, BGP prefix, registry country and reverse DNS — answered from public routing data, no connection to the address. | — |
| [NTP Server Test](/ntp-test) | Query a time server: stratum, clock offset and delay per sample, leap indicator, version. | [NTP monitor](/docs/monitors/performance#ntp) |

## Web

| Tool | What it does | Continuous version |
| --- | --- | --- |
| [MCP Server Checker](/mcp-server-checker) | Test a Model Context Protocol server: handshake, capabilities and tool inventory. | [MCP server monitor](/docs/monitors/mcp) |
| [SSL Certificate Check](/ssl-checker) | Certificate validity, chain and days until expiry. | [SSL / TLS monitor](/docs/monitors/certificates#ssl--tls-certificate) |
| [SSL/TLS Grade](/ssl-grade-checker) | Grade a server's TLS configuration A+ to F — protocols, ciphers, forward secrecy, post-quantum readiness, HSTS and certificate — with the exact reasons. | [SSL / TLS monitor](/docs/monitors/certificates#ssl--tls-certificate) with the grade option |
| [HTTP Headers](/http-header-checker) | Inspect the response headers a URL returns. | [Website monitor](/docs/monitors/web) |
| [Security Headers Checker](/security-headers-checker) | Audit HSTS, CSP, X-Frame-Options, nosniff, Referrer-Policy and Permissions-Policy with the value of each and what a missing one leaves open. | [Website monitor](/docs/monitors/web) |
| [HSTS Checker](/hsts-checker) | Strict-Transport-Security max-age, includeSubDomains, preload — and whether the site qualifies for the browser preload list. | [Website monitor](/docs/monitors/web) |
| [HTTP Status Checker](/http-status-checker) | The status code a URL returns from a real probe location, with timing and headers. | [Website monitor](/docs/monitors/web) |
| [Redirect Checker](/redirect-checker) | Follow every redirect hop — status, Location, timing — to the final URL, with loops, downgrades and temporary redirects flagged. | [Website monitor](/docs/monitors/web) |
| [WebSocket Tester](/websocket-tester) | Open a ws:// or wss:// connection: handshake time, ping/pong, and an optional message with a pattern-matched reply. | [WebSocket monitor](/docs/monitors/performance#websocket) |
| [SSL Expiry Checker](/ssl-expiry-checker) | Days until the certificate a host serves expires, with issuer and chain trust. | [SSL / TLS monitor](/docs/monitors/certificates#ssl--tls-certificate) |
| [TLS Version Checker](/tls-version-checker) | Which TLS versions a server accepts (1.0–1.3) and the cipher suites for each, graded. | [SSL / TLS monitor](/docs/monitors/certificates#ssl--tls-certificate) with the grade option |
| [API Tester](/api-tester) | Send a one-off HTTP request (any method, headers, body) and inspect status, headers and body. | [API monitor](/docs/monitors/api) |
| [CDN Checker](/cdn-checker) | Global CDN analysis: provider (60+ recognised), edge per region, cache behaviour and a health grade. | [CDN monitor](/docs/monitors/performance#cdn) |
| [Sitemap Checker](/sitemap-checker) | Validate that `sitemap.xml` is present and well-formed. | [Sitemap monitor](/docs/monitors/performance#sitemap) |
| [Sitemap Validator](/sitemap-validator) | The same check, framed around validity: location, XML format, URL count and a sample fetch for broken entries. | [Sitemap monitor](/docs/monitors/performance#sitemap) |
| [Brotli Checker](/brotli-checker) | Whether responses are served with Brotli compression. | [Brotli monitor](/docs/monitors/performance#brotli-compression) |
| [Gzip Compression Test](/gzip-test) | Which encoding (gzip / Brotli / none) a URL negotiates and the bytes saved. | [Brotli monitor](/docs/monitors/performance#brotli-compression) |

## Email

| Tool | What it does | Continuous version |
| --- | --- | --- |
| [Email Health](/email-policy-checker) | SPF, DMARC and DKIM for a domain in one view. | [Email policy monitor](/docs/monitors/email#email-policy-spf--dmarc--dkim) |
| [SPF Checker](/spf-record-checker) | Validate a domain's SPF record and the mechanisms it includes. | [Email policy monitor](/docs/monitors/email#email-policy-spf--dmarc--dkim) |
| [DKIM Checker](/dkim-record-checker) | Check a domain's DKIM signing record for a selector. | [Email policy monitor](/docs/monitors/email#email-policy-spf--dmarc--dkim) |
| [DMARC Checker](/dmarc-record-checker) | Check a domain's DMARC policy and alignment settings. | [Email policy monitor](/docs/monitors/email#email-policy-spf--dmarc--dkim) |
| [Email Header Analyzer](/email-header-analyzer) | Paste raw headers: delivery path with per-hop delays, SPF/DKIM/DMARC verdicts and alignment — analyzed in your browser. | — |
| [SPF & DMARC Generator](/spf-dmarc-generator) | Build ready-to-publish SPF and DMARC records with provider presets and a lookup counter. | — |
| [SMTP Server Test](/smtp-test) | Open a real SMTP session on port 25, 465 or 587: banner, STARTTLS, reverse DNS match and an open-relay probe. No message is sent. | [SMTP monitor](/docs/monitors/email#smtp) |

## Calculators

Everything here runs client-side in your browser.

| Tool | What it does | Related |
| --- | --- | --- |
| [Uptime / Downtime Calculator](/uptime-calculator) | Turn an uptime percentage (99.9%…) into allowed downtime per day, month and year. | [Reports](/docs/reports) |
| [Error Budget Calculator](/error-budget-calculator) | SLO error budgets, burn rates and exhaustion projections. | [Glossary: SLO](/docs/reference/glossary) |
| [Cron Expression Tester](/cron-expression-tester) | Explain any cron expression and preview its next runs in your timezone. | [Cron job monitor](/docs/monitors/heartbeat) |
| [JSON Formatter & JSONPath](/json-formatter) | Format, validate and query JSON with JSONPath. | [API monitor assertions](/docs/monitors/api) |
| [Timestamp Converter](/unix-timestamp-converter) | Unix epoch to human dates and back; seconds and milliseconds auto-detected. | — |
| [Subnet Calculator](/subnet-calculator) | IPv4 CIDR math: masks, ranges, binary breakdowns and subnet splitting. | — |
| [IPv6 Subnet Calculator](/ipv6-subnet-calculator) | 128-bit prefixes, address counts, `ip6.arpa` and address classification. | — |
| [Bandwidth Calculator](/bandwidth-calculator) | Transfer times for any size and speed, or the bandwidth a deadline needs. | — |
| [Chmod Calculator](/chmod-calculator) | Unix permissions: rwx checkboxes to octal, symbolic and the `chmod` command. | — |
| Landings: [Crontab Generator](/crontab-generator) · [Epoch Converter](/epoch-converter) · [CIDR Calculator](/cidr-calculator) · [SLA Calculator](/sla-calculator) | The cron, timestamp, subnet and uptime calculators opened for those questions, each with its own introduction and FAQ. | — |

> **Info**
>
> Like a tool? Every "continuous version" above is a [monitor type](/docs/monitors)
> — turn a one-off check into continuous monitoring with alerting, incidents
> and a status page in a couple of clicks. AI agents can run these same
> checks on demand through
> [live diagnostics](/docs/api/diagnostics) over the
> [REST API and MCP server](/docs/api).

---

Canonical page: https://watchfor.io/docs/tools · All docs: https://watchfor.io/docs · Site guide: https://watchfor.io/llms.txt
