How It Works

How AcuityScan works.

One runs 350+ checks and scores your entire digital presence. Or use any of our 21+ individual tools for a quick specific lookup.

Three steps. 60 seconds.

1

Scan

Enter any domain. The fires 350+ checks across 8 categories simultaneously — email, DNS, SSL, performance, SEO, accessibility, privacy, and mobile.

2

Score

Every category gets its own 0-100 score. These feed into a unified AcuityScan Score that tells you exactly how healthy your online presence is at a glance.

3

Fix

Every issue comes with a plain-English explanation, its business impact, and a copy-paste fix. Export the whole report as a PDF for clients.

Two ways to use AcuityScan

Full 350+ check audit
  • Unified health score weighted across all 8 categories
  • All checks run in parallel — results stream in ~60 seconds
  • Prioritized issues with severity, business impact, and copy-paste fixes
  • Export as PDF report for clients or your team

Best for

→ Initial website audit→ Pre-launch checks→ Competitor research→ Regular health checkups→ Client reporting→ Proving your work
Run

Individual Tools

21+ standalone diagnostics
  • Instant answers — one tool, one question, no waiting
  • Detailed raw data — DNS records, WHOIS, full headers, SMTP logs
  • Troubleshooting mode — verify DNS changes, confirm delistings, check certs

Best for

→ "Did my DNS propagate?"→ "Am I blacklisted?"→ "When does this expire?"→ "Is my SSL correct?"→ "What tech do they use?"→ "Where does this redirect?"
Browse All Tools

What the checks

8 categories, each running dozens of individual checks in parallel.

Email Deliverability

~110 checks

SPF, DKIM, DMARC, MX, PTR, MTA-STS, TLSRPT, 80+ blacklists, SMTP test, Google/Yahoo 2024 compliance

DNS Health

~35 checks

A, AAAA, NS, MX, TXT, SOA, CAA, DS records, DNSSEC, TTL analysis, 20+ global resolver propagation, subdomains, reverse IP

Threat Intelligence

~35 checks

SSL/TLS certs + chain validation, security headers (CSP/HSTS/10+ more), Google Safe Browsing, CVE scan for detected tech stack, subdomain takeover detection, CORS misconfiguration, supply chain / SRI audit, breach detection, WHOIS privacy + expiry alerts

Performance

~75 checks

TTFB, Core Web Vitals via Google PSI, compression, CDN, images, render-blocking scripts, tech stack (60+ technologies)

Technical SEO

~30 checks

Title, meta description, headings, canonical, OG/Twitter, robots.txt, sitemap, Schema.org validation, broken links, noindex detection

Accessibility

~120 checks

Full axe-core WCAG 2.1 AA at desktop + mobile viewports, 38+ custom HTML checks, form labels, ARIA, landmarks, contrast

Privacy & Cookies

~35 checks

28+ tracker detection, consent banner compliance, pre-consent violations, privacy policy, CCPA, Google Consent Mode v2

Mobile & UX

~15 checks

Viewport, touch targets, form input types, font sizes, mobile nav, responsive images, PWA features, interstitials

Deep dive: What each category checks

Every module runs dozens of specific checks. Here is exactly what AcuityScan tests in each category.

Email Deliverability

Email authentication is the #1 factor in whether your messages reach inboxes or land in spam. AcuityScan checks every layer of your email security stack — from SPF alignment and DKIM signing to DMARC enforcement policies. We query 80+ real-time blacklists (the same ones MXToolbox uses) and verify your mail server configuration against Google and Yahoo's 2024 bulk sender requirements.

SPFDKIM (16 selectors)DMARCMX RecordsPTR/Reverse DNSMTA-STSTLSRPTBIMI80+ BlacklistsGoogle/Yahoo Compliance

DNS Health

Your DNS configuration is the foundation everything else depends on — email delivery, SSL certificates, CDN routing, and basic website reachability. AcuityScan queries 20+ DNS resolvers worldwide (Google, Cloudflare, Quad9, OpenDNS, and regional resolvers across 6 continents) to verify your records are correct and fully propagated. We check DNSSEC signing, flag misconfigured TTLs, and detect nameserver redundancy issues.

A/AAAA RecordsMX RecordsTXT RecordsNS RecordsSOACAADS/DNSSECTTL AnalysisGlobal PropagationNameserver Redundancy

SSL/TLS Security

An SSL certificate is the minimum — but the gap between 'has SSL' and 'properly secured' is where most websites fail. AcuityScan tests TLS protocol versions (1.0 through 1.3), analyzes cipher suite configuration for weak or deprecated ciphers, validates the full certificate chain, and checks six critical security headers. We flag everything from missing HSTS headers to certificates approaching expiry.

TLS 1.0-1.3Cipher SuitesCertificate ChainHSTSCSPX-Frame-OptionsReferrer-PolicyPermissions-PolicyForward SecrecyAEAD Ciphers

Performance

Page speed directly impacts revenue — Google's data shows that a 1-second delay in mobile load time reduces conversions by up to 20%. AcuityScan measures Time to First Byte, analyzes compression (gzip/brotli), detects CDN usage, audits image optimization, flags render-blocking scripts, and inventories every third-party resource loaded on your page. We also detect 60+ technologies in your stack to identify potential bottlenecks.

TTFBCore Web VitalsCompressionCDN DetectionImage OptimizationRender-Blocking ResourcesThird-Party ScriptsResource HintsCache HeadersTech Stack (60+)

Technical SEO

Search visibility starts with technical foundations. AcuityScan validates your title tags, meta descriptions, heading hierarchy, canonical URLs, Open Graph tags, and structured data markup. We check your robots.txt, verify your XML sitemap, validate Schema.org JSON-LD against the official spec (not just detect it), and flag issues like missing alt text, duplicate H1 tags, and broken canonical references.

Title & MetaHeading HierarchyCanonical URLOpen GraphTwitter Cardsrobots.txtXML SitemapSchema.org ValidationAlt TextInternal Links

Accessibility (WCAG 2.1 AA)

Web accessibility lawsuits under ADA Title III have increased 300% since 2018. AcuityScan runs a full axe-core audit at both desktop (1280px) and mobile (390px) viewports — the same engine used by Deque, Microsoft, and Google. On top of that, we run 38+ custom checks for issues axe-core misses: empty headings, empty buttons, broken ARIA references, suspicious alt text (filenames), overly long alt text, orphaned form labels, data tables without headers, document links without format warnings, audio/video without captions, onclick without keyboard support, missing header/footer landmarks, noscript fallback, prefers-reduced-motion, and more.

axe-core WCAG 2.1 AADesktop + Mobile ViewportsLandmarksHeading StructureForm LabelsARIA AttributesSkip LinksAlt TextKeyboard NavigationReduced MotionEmpty Headings/ButtonsBroken ARIA RefsSuspicious Alt TextTable StructureDocument LinksMedia Captions

Privacy & Cookies

GDPR fines exceeded €2.1 billion in 2023, and CCPA enforcement is accelerating. AcuityScan detects 28+ known tracking scripts (Google Analytics, Facebook Pixel, Hotjar, Mixpanel, and more), checks whether they load before user consent, verifies cookie consent banner presence, and looks for privacy policy and CCPA 'Do Not Sell' links. We also detect Google Consent Mode v2 implementation.

28+ Tracker DetectionPre-Consent ViolationsConsent BannerPrivacy PolicyCCPA LinksGoogle Consent Mode v2Insecure Resources

Mobile & UX

Over 60% of web traffic is mobile, and Google uses mobile-first indexing for every site. AcuityScan checks viewport configuration, touch target sizing, form input types (does your phone field trigger the number keyboard?), font sizes that cause iOS zoom bugs, mobile navigation patterns, responsive image implementation, and Progressive Web App features. We also detect intrusive interstitials that Google penalizes in search rankings.

Viewport MetaTouch TargetsForm Input TypesFont SizesMobile NavigationResponsive ImagesPWA FeaturesInterstitialsHorizontal OverflowText Readability

All 21+ individual tools

Each tool gives you detailed results for one specific check — better than MXToolbox, SSL Labs, and the rest.

How AcuityScan compares

The others each do one thing well. AcuityScan gives you all of them — plus a unified score, plain-English fixes, and a shareable report — in a single 60-second scan.

AcuityScanMXToolboxSSL LabsGTmetrixWAVE
Primary focusFull digital auditEmail, DNS, blacklistsTLS / SSL deep divePage speedAccessibility (WCAG)
Categories covered8311 (+ light SEO)1
Unified 0–100 health scoreYesPass/failA–F gradeLetter gradeIssue count
Severity-ranked findingsYesPass/failPass/failYesYes
Copy-paste fixes in reportYesPartialGuidelines only
Shareable link / PDF exportYes / ProPaid tierLink onlyPaid tier
No account (full scan)YesLimitedYesYesYes
Monitoring & alertsIncluded in Pro$129+/mo$11+/mo
Starting paid tier$29 / mo$129 / moFree only$11 / moFree only

Comparisons based on publicly listed features as of 2026. Competitor capabilities change — if anything here is outdated, let us know.

Frequently asked questions

Everything you need to know about scanning with AcuityScan.

How accurate is the AcuityScan Score?
The AcuityScan Score is a weighted average across all 8 categories. Performance (20%) and email deliverability (15%) carry the most weight because they have the biggest impact on revenue and customer trust. SSL, SEO, and accessibility each contribute 10-15%. The weights are based on real-world business impact data and adjusted as web standards evolve.
Can AcuityScan replace Google Lighthouse?
For performance testing, AcuityScan uses Google's PageSpeed Insights API — the same data source as Lighthouse. But AcuityScan goes far beyond performance: email authentication, DNS health, SSL cipher analysis, privacy compliance, and 60+ technology detections are areas Lighthouse doesn't cover at all.
Does scanning affect my website?
No. AcuityScan makes standard HTTP requests — the same kind Google's crawler makes. We don't run any code on your server, modify any files, or cause any load that would affect your visitors. The accessibility scanner runs axe-core in a sandboxed iframe in your browser, not on your server.
What if I disagree with a finding?
Every finding includes a severity level and business impact explanation. Info-level findings are suggestions, not requirements. If a finding doesn't apply to your situation (for example, HSTS preloading on a development site), you can safely skip it. The score gives you a general health picture, not a mandatory checklist.
How often should I scan my site?
After any major change (DNS migration, SSL renewal, new deployment, plugin updates) and at least once a month for routine monitoring. Pro plan users get monthly auto-rescans plus 24/7 threat alerts (blacklist listings, new CVEs, SSL expiry, subdomain takeover) — Agency adds weekly auto-rescans across every saved domain.

Ready to see your score?

60 seconds. 350+ checks. No signup required.