Try It Now

Year: 2026

Subdomain takeover explained — a dangling CNAME on your domain still points at a third-party service that released the name, letting someone else serve content from your subdomain | SelfHack AI

Subdomain Takeover: How Dangling DNS Records Hand Attackers Your Domain

Subdomain takeover: how a dangling CNAME lets someone else serve content on your domain, how to find them safely, and how to prevent the next.

Read More
How to check open ports on your own domain safely and legally — listening services, firewall reachability, nmap and ss on assets you own | SelfHack AI

How to Check Open Ports on Your Own Servers (and What to Close)

How to check open ports on infrastructure you own: the commands that work, what each exposed service means, and the decision rule for what to close.

Read More
DMARC check explained — SPF authorises sending IPs, DKIM signs the message, and DMARC aligns both to the visible From domain before telling receivers to reject spoofed mail | SelfHack AI

DMARC Check: How to Test Whether Anyone Can Spoof Your Domain

DMARC check: find out whether anyone can send email as your domain, how to read your SPF, DKIM and DMARC records, and how to reach enforcement.

Read More
Security headers check overview — the HTTP response headers a security headers check looks for: Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options nosniff, Referrer-Policy and Permissions-Policy | SelfHack AI

Security Headers Check: What Each Header Does and How to Test Yours

Security headers check: what HSTS, CSP, X-Frame-Options and Referrer-Policy each stop, how to test yours, and how to fix what is missing.

Read More
How to find subdomains of a domain — passive OSINT sources including Certificate Transparency logs, DNS records, passive DNS and web archives feeding a subdomain inventory | SelfHack AI

How to Find Subdomains: A Practical Guide to Mapping Your Own Attack Surface

How to find subdomains of a domain you own: certificate transparency, passive DNS, brute force and resolution — plus what to do with the list you get.

Read More
Free security checks — six things to test on your own domain: subdomains, security headers, DMARC, open ports, subdomain takeover and SSL TLS | SelfHack AI

Free Security Checks: 6 Things to Test on Your Own Domain

Free security checks: six tests you can run on your own domain today — subdomains, headers, DMARC, open ports, dangling DNS and TLS, with real commands.

Read More
Aikido alternative — scanners like Aikido find and flag potential issues, while SelfHack AI autonomously exploits and proves what is actually exploitable | SelfHack AI

Aikido Alternative in 2026: The Autonomous Pentest Scanning Can’t Replace

Aikido alternative for real pentesting: scanners find and flag, SelfHack AI exploits and proves — full-stack, exploit-validated, with published research.

Read More
XBOW alternative — SelfHack AI vs XBOW: both autonomous, but SelfHack AI covers the full stack from web to CPU/GPU firmware with published exploit-validated research | SelfHack AI

XBOW Alternative: Why Security Teams Choose SelfHack AI in 2026

Looking for an XBOW alternative? SelfHack AI matches autonomous web depth, then covers cloud, firmware & confidential computing — with published research.

Read More
Best AI pentest tools 2026 ranked — SelfHack AI 95, XBOW 78, Terra Security 74, Aikido 66 on overall autonomous penetration testing capability | SelfHack AI

Best AI Pentest Tools in 2026: SelfHack AI, XBOW, Terra & Aikido Compared

The best AI pentest tools in 2026 compared: SelfHack AI, XBOW, Terra & Aikido — autonomy, exploit validation, and full-stack coverage, ranked.

Read More
Supply chain penetration testing — Slovakia's 279 backdoored NERO R-ONE traffic cameras with SMS-triggered remote shell, disabled SecureBoot and passwordless live streams | SelfHack AI

Supply Chain Penetration Testing: What Slovakia’s Backdoored Cameras Reveal

Supply chain penetration testing after Slovakia’s backdoored cameras: the SMS shell, SecureBoot-off firmware, and how to test hardware you cannot trust.

Read More