Start with what happened

“I got an email and I’m not sure it’s real.”Email Header Analyzer → “Could someone send email pretending to be my business?”Business Email Security Check → “I need a strong password I can actually remember.”Password Generator → “I’m setting up an app and need a signing secret or API key.”JWT Secret or API Key Generator →

All six tools

Business Email Security Check

stashgrid.site/emailcheck/

Enter a domain and see whether its SPF, DKIM and DMARC records would stop someone forging email from it, plus MTA-STS and DNSSEC, each explained in plain English with the fix.

Sends: the domain name, to Cloudflare public DNS

Email Header Analyzer

stashgrid.site/headers/

Paste a raw email header to see which server really delivered it, whether authentication passed for the address you can see, and which lines the sender could have faked.

Sends: nothing — reads in your browser

Password Generator

stashgrid.site/password/

Random passwords, passphrases, and a memorable mode that builds a password from your own keywords, with padding and symbols doing the real work against guessing.

Sends: nothing — generated in your browser

API Key Generator

stashgrid.site/password/api-key-generator/

Random API keys and access tokens with prefixes such as sk_live_, in base62, URL-safe or hex, ready to paste into a .env file.

Sends: nothing — generated in your browser

JWT Secret Generator

stashgrid.site/password/jwt-secret-generator/

Signing secrets for HS256, HS384 and HS512 tokens, webhook signatures and sessions, sized to what the algorithm actually requires.

Sends: nothing — generated in your browser

htpasswd Generator

stashgrid.site/password/htpasswd-generator/

A .htpasswd line from your own username and password for Apache Basic Auth, with APR1 MD5 output, SHA-1, bcrypt commands and the matching .htaccess snippet.

Sends: nothing — hashed in your browser

Email security has two halves

Most email fraud against a small business works one of two ways, and each needs a different tool. In the first, a criminal sends mail that claims to come from your domain — a fake invoice to your customers, or a “please change our bank details” message to your suppliers. Whether that works is decided by three public DNS records on your domain, and the Business Email Security Check reads them. You fix this once, on your own domain, and it protects everyone who receives mail in your name.

In the second, a message lands in your inbox and you need to decide whether to trust it. The visible From line proves nothing, because the sender typed it. What does carry weight is the trail your own mail provider added when the message arrived: which server handed it over, and whether that server was authorised to send for the domain it claimed. The Email Header Analyzer reads that trail and separates the lines your provider wrote from the ones the sender could have invented.

The same three standards sit behind both tools. SPF lists the servers allowed to send for a domain. DKIM signs each message so a receiver can confirm it came from that domain’s mail system unaltered. DMARC ties them to the address people actually see, and tells receivers what to do when a message fails. A domain with SPF and DKIM but no enforcing DMARC policy is still easy to impersonate, and it is one of the most common gaps on small-business domains.

Passwords and secrets are not the same job

A password is typed by a person; a secret is read by a machine. That difference changes what “strong” means. For the handful of passwords you have to remember, length matters far more than odd characters, and a long passphrase beats a short jumble. The Password Generator covers both random passwords and memorable ones built from your own words.

Secrets have no such trade-off, because nobody needs to remember them. An API key, a JWT signing secret or a webhook secret should be pure randomness, sized to the job: the JWT Secret Generator follows the rule that an HMAC key should be at least as long as the hash it feeds, and the API Key Generator adds a readable prefix so a leaked key can be recognised by secret scanners. The htpasswd Generator sits between the two: you choose the password, and it produces the hashed line Apache stores.

What leaves your browser

Security tools ask you to paste sensitive things, so this is stated tool by tool rather than as a blanket promise. It was measured by watching each page’s network requests while using it.

ToolWhat you enterWhere it goes
Business Email Security CheckA domain nameCloudflare’s public DNS-over-HTTPS resolver, to look up the records. Never a StashGrid server.
Email Header AnalyzerA raw email headerNowhere. Parsed in the page.
Password GeneratorOptions, and optional keywordsNowhere. Generated in the page.
API Key, JWT Secret and htpasswd GeneratorsOptions, and for htpasswd your username and passwordNowhere. Generated and hashed in the page.

Like every StashGrid page, these pages also load Google ads and analytics. The full picture is in the privacy policy.

Questions

Which tool should I use if I think an email is a phishing attempt?

Use the Email Header Analyzer. Paste the raw header of the message and it shows which server actually handed the message to your provider, whether SPF, DKIM and DMARC passed, and which delivery lines were written by the sender and therefore cannot be trusted. The Business Email Security Check answers a different question: whether a domain you own can be impersonated.

Do these security tools send what I type to StashGrid?

No. The header analyzer and all four generators run entirely in your browser and make no network request with what you type. The Business Email Security Check sends the domain name you enter to Cloudflare's public DNS-over-HTTPS resolver, because DNS records can only be read by asking a resolver. It never goes to a StashGrid server. Every page also loads ads and analytics, as described in the privacy policy.

What is the difference between SPF, DKIM and DMARC?

SPF lists the servers allowed to send mail for a domain. DKIM adds a cryptographic signature proving a message came from the domain's mail system and was not altered. DMARC tells receivers what to do when a message claiming to be from the domain fails those checks, and requires the passing domain to match the visible From address. Until DMARC is set to quarantine or reject, receivers are not told to act on a failure, so a forged message can still be delivered.

Should I use a random password or a memorable one?

For anything a password manager fills in for you, use a long random password. For the few passwords you must type from memory, such as the password manager itself, a long memorable passphrase is fine as long as it is not built from facts someone could find about you. Server secrets, API keys and JWT signing secrets should always be random and never memorable.

How long should a JWT secret or API key be?

For an HMAC-signed JWT, use at least as many random bytes as the hash output: 32 bytes for HS256, 48 for HS384 and 64 for HS512. For API keys, aim for at least 128 bits in the random part, which is 22 base62 characters or 32 hex characters; the generator defaults to more. Encoding the bytes as hex or base64url changes the length of the string, not its strength.