Toolbox
Useful tools, free, no sign-up.
Designed for experienced Microsoft 365 administrators, with a gentler section for everyone. Nothing is stored: your inputs never leave your browser, except the domain name being tested.
For administrators
Email posture of a domain
MX, SPF, DKIM, DMARC, MTA-STS, BIMI and DNSSEC in one request. Common DKIM selectors are tested automatically; add your own.
Password and passphrase generator
Generated locally with the browser's cryptographic randomness. Nothing is sent.
Has this password leaked?
Anonymous check: only the first five characters of the SHA-1 hash are sent to the public breach service (k-anonymity). The password never leaves your browser.
JWT token decoder
Local decoding of headers and claims (aud, iss, scp, roles, exp…). Useful to diagnose a consent or a permission. No signature verification.
Suspicious link decoder
Paste a link received by email or message: the decoder reveals the real destination behind security wrappers and URL shorteners, spots look-alike domains, deceptive characters and tracking parameters. Nothing is opened or sent: everything is read in your browser.
Entra and AD identifier translator
Paste an ObjectId (GUID), an ImmutableID (Base64), a cloud SID (S-1-12-1-…) or an Active Directory SID: the format is detected and translated into the others. Handy for Entra Connect, ACLs and logs. Everything stays in your browser.
PowerShell script generator (Graph and Entra)
Ready-to-adapt scripts with the required Graph permissions and guardrails. Always review before running in production.
For everyone
Express self-assessment
Tick what is in place. The score updates live.
Five habits that really protect
- Enable two-step verification everywhere possible, especially on email.
- One password per service, kept in a password manager.
- Beware of urgency: a message that rushes you is a message to verify.
- Update your devices as soon as offered.
- Back up what matters, and test a restore once a year.
Spot a Phishing attempt in 30 seconds
- The sender address does not exactly match the expected domain.
- You are asked to click, pay or enter a password quickly.
- The displayed link and the real link differ (hover before clicking).
- The tone, language or layout does not look like usual.
- When in doubt: do not click, contact the sender through another channel.