Free tool

Scan your site, free. See what addresses a bot takes.

Every day, automated programs comb the internet and copy any email address left in the open. That is what feeds spam. The tool below reads your site exactly the way they do — and tells you on the spot what they would find.

  • Free
  • No account
  • Nothing to install
  • The report — only to your email
  1. 01

    Type your site's address

    That is all. No account, no card, no personal data at this step.

  2. 02

    We read it like a bot

    Up to 40 pages, starting with Contact, About and Team — where addresses usually live.

  3. 03

    See the result instantly

    The number appears on screen. The exact list travels only to your email, so it never lands in the wrong hands.

Why it matters

Spam does not start in your inbox. It starts on your page.

Nearly every unwanted message has the same story behind it: an address left in the open, a program that copied it, and a list resold over and over, year after year. Nobody "hacked" anything — someone simply read what was public.

The good news: this exposure can be seen, and it can be closed. Step one is knowing exactly what a bot sees on your site — which is what the scan above does.

What we check

Five checks, all stated openly.

No black box. These are exactly the things we look at — explained in plain language, not in developer-speak.

01

Addresses left in the open

Any email address visible in the page — including the ones "disguised" with at and dot written out as words. That trick is 20 years old, and today’s bots read 16 such disguises without breaking step.

Why it matters: An address visible for a single day can mean spam for years.

02

Addresses that get guessed

info@, office@, contact@ — even if they appear nowhere on your site, spam senders try them automatically on every domain, just in case. We count them separately, so you know what to expect.

Why it matters: You can receive spam on addresses you never published.

03

Personal addresses on a company site

A Gmail or a Yahoo on the team page. The site will change; the lists the address landed on will not — and the spam goes to the person, in their personal inbox.

Why it matters: You protect your colleagues, not just the company.

04

Forms with no gatekeeper

A contact form that never checks whether the sender is a person or a program. A script can submit it a thousand times a night — and every submission becomes a message in your inbox.

Why it matters: Some of the odd "offers" you receive arrive through your own form.

05

Who may send email in your name

Every domain can state publicly who is allowed to send mail on its behalf — SPF and DMARC, by their technical names. We check whether yours does. Without that rule, anyone can pose as you, and your legitimate mail lands in spam more often.

Why it matters: This is not only about the spam you receive — it is about trust in the email you send.

Why we built it

We wrote this tool after fixing our own inbox.

We are not selling a theory. On some days we received as many as 20 spam messages, and the folder had to be emptied by hand every two or three days. On 6 August 2026 we took the address out of cittago.com's markup and put an invisible gatekeeper on the forms. The bots have not been back.

Before up to 20 spam messages a day

Since 6 August 0 from bots

The rare hand-typed message still gets through — nothing stops those. From machines: none.

9 days

without a single bot-sent spam message

0 min

a day lost to the spam folder

Real data from the Cittago inbox · protection live since 6 August 2026 · the counter updates itself

The tool's limits

What it does — and what it does not.

We would rather you heard the limits from us than discovered them yourself.

Does

  • Reads up to 40 pages, starting where addresses usually live
  • Recognises 16 common address disguises, not just plain text
  • Counts the forms that carry no bot check at all
  • Checks the public sending rules of your domain
  • Sends you the report with every address, the page it sits on and what it means

Does not

  • It does not see the whole site. We stop at 40 pages — a large site has more.
  • It does not read PDFs and images. An address inside a catalogue or a photo will not appear in the report.
  • It does not see what JavaScript builds. If your address is made that way, a bot cannot see it — and that is a good sign.
  • It does not click or submit anything. It only reads, like any visitor. Forms are looked at, never tested.
  • It is not a security audit. It measures address exposure, not your site's vulnerabilities.

FAQ

The tool, in short.

What first-time users usually ask us.

What exactly does this tool do?

It opens up to 40 pages of your site — starting from the address you give us and from the sitemap, contact pages first — and counts the email addresses an automated program could copy. You see the number on screen; the exact list, with each address's page and an explanation, arrives by email.

Why don't you show the addresses right on the page?

Because the tool would then become exactly the thing we built it against: anyone could type in somebody else’s site and walk away with a ready-harvested list of addresses. The report goes only to the address that asked for it.

How long does it take, and what does it cost?

Usually under a minute — it depends on how many pages the site has and how fast it responds. It is free: no account, no card, no "trial period".

What happens to my data?

We use your name and address once: to send you the report. We subscribe you to nothing, and the scan results go to nobody else.

Can the scan affect my site?

No. We read at most 40 pages, once, at the pace of an ordinary visitor. We submit no forms, click no buttons, and we identify ourselves openly, with our bot's name.

Why did it find zero addresses when I know I have one on the site?

Most likely your address does not exist as text in the page — it is built by JavaScript or shown as an image, so a bot reading the markup cannot see it. That is the good result. Our own address is protected exactly the same way.

Does it find absolutely every address?

No, and we would rather say so ourselves: it sees only what loads with the pages it reads. What it finds is real; what it does not find is not a guarantee.

The scan takes a minute. Spam lasts years.

See what is out in the open on your site — and if you want it gone, you know where to find us.

·First paint — when something appeared·Server response — before anything could load·Page ready — when you could interact
Page loaded in ·