/api/perimeter/ct-logs Certificate Transparency logs
All certs ever issued for domain + subdomains (crt.sh).
Personal perimeter audit
Open-target perimeter + performance dashboard. Any syntactically valid domain is scannable —
guard rails are syntactic validation, per-source upstream quotas, and Cloudflare Access JWT
gating this dashboard to a single user. See docs/SECURITY.md.
Run all
Perimeter
/api/perimeter/ct-logs All certs ever issued for domain + subdomains (crt.sh).
/api/perimeter/dns-current A / AAAA / MX / TXT / NS / SOA / CAA via Cloudflare DoH.
/api/perimeter/dns-propagation Fan out same query across 4 public resolvers + 8 simulated regions via Google DoH ECS. Grid view + consensus + divergent rows.
/api/perimeter/headers-ssl HTTP response headers + security-header grading + most-recent TLS cert.
/api/perimeter/subdomains-passive Union of crt.sh + AlienVault OTX + HackerTarget hostnames for the domain. Optional OTX_API_KEY secret bypasses public rate limit.
/api/perimeter/whois Registrar, expiry, nameservers, statuses via RDAP.
Performance
/api/performance/ttfb-single Time-to-first-byte from the nearest Cloudflare PoP to the Worker.