The checks, explained
What we check on your domain, and why it matters.
52 checks across your email, DNS, website encryption, browser protections, registration and reputation. Each one says what it looks at, what goes wrong for your business when it fails, and how to fix it.
Email Authentication
Whether other mail servers can tell your real email from a forgery, and whether it gets delivered.
- SPF record checkSPF lists the servers allowed to send email as your domain. Without a valid one, your mail lands in spam and forgeries get through.
- SPF lookup limit checkAn SPF record may trigger at most 10 DNS lookups. Past that, receivers treat it as broken and your mail loses its SPF pass.
- SPF policy strength checkThe ending of your SPF record (-all, ~all, ?all or +all) decides what receivers do with mail from servers you did not list.
- DKIM record checkDKIM puts a tamper-proof signature on every email you send. Receivers use it to prove the message really came from you.
- DMARC record checkDMARC tells receivers what to do with email that fails SPF and DKIM, and sends you reports on who is sending as your domain.
- MX record checkMX records tell the internet which servers receive email for your domain. Wrong or missing MX means lost mail.
- MTA-STS checkMTA-STS tells other mail servers they must use encryption when delivering to you, closing off downgrade and interception attacks.
- TLS-RPT checkTLS-RPT asks other mail servers to report when they could not deliver to you securely, so you hear about problems before mail is lost.
- DNS lookup checkBefore we can check anything about your email, your domain's DNS has to answer. This check says when it did not.
DNS Health
The records that point the world at your website and mail. If these break, everything on the domain breaks.
SSL/TLS & Website
Whether visitors reach your site over a trusted, encrypted connection without a browser warning.
- Website reachability checkWhether your website answered at all. If this fails, most other website checks could not run.
- HTTPS connection checkWhether your site completes a secure HTTPS connection with a certificate browsers trust.
- SSL certificate checkThe certificate your website presents: who issued it, which names it covers, and when it expires.
- Certificate expiry checkAn expired SSL certificate turns your website into a browser warning. We check how many days yours has left.
- Certificate trust and chain checkWhether browsers trust the certificate: issued by a real authority, served with its full chain, and not revoked.
- Certificate name checkThe certificate has to name the exact hostname a visitor types. If it names something else, browsers refuse it.
- Certificate key and signature checkWhether your certificate uses a key and signature strong enough for today's browsers.
- TLS version checkWhether your server still accepts retired encryption (TLS 1.0 and 1.1) and whether it offers the current one (TLS 1.3).
- CAA record checkA CAA record names the certificate authorities allowed to issue certificates for your domain, and blocks the rest.
- HTTP to HTTPS redirect checkVisitors who type your address without https:// should be sent to the secure version automatically.
- HTTP status checkThe status code your homepage answers with. Anything but a success means visitors and search engines are not seeing your site.
- Response time checkHow long your server takes to answer. Over a second feels slow to visitors; over three loses them.
- Mixed content checkAn HTTPS page that loads images or scripts over plain HTTP. Browsers block them or mark the page as not fully secure.
- Parked domain checkWhether your domain is showing a registrar's parking page (ads, "this domain may be for sale") instead of your website.
- Cross-domain redirect checkYour domain sends visitors to a different domain. Fine if intended; worth knowing if not.
Security Headers
Instructions your site sends to browsers that shut down common attacks on your visitors.
- HSTS checkHSTS tells browsers to only ever use HTTPS for your site, so a visitor on public Wi-Fi cannot be quietly downgraded.
- Content-Security-Policy checkCSP tells browsers which scripts your site is allowed to run, which stops most injected code from running on your visitors.
- X-Frame-Options checkStops other websites from loading yours inside an invisible frame to trick visitors into clicking things (clickjacking).
- X-Content-Type-Options checkStops browsers guessing a file's type, which blocks a class of attacks that disguise scripts as images or text.
- Referrer-Policy checkControls how much of your page addresses leak to other sites when visitors click a link.
- Permissions-Policy checkSwitches off browser features your site does not use (camera, microphone, location) so injected code cannot use them either.
- Cross-origin policy checkTwo headers that isolate your pages from other sites a visitor has open, closing off cross-site data leaks.
- X-XSS-Protection checkA retired header. Modern browsers ignore it, and the old filter it switched on could be abused, so it is best set to 0.
Page Security
What your homepage lets run in a visitor's browser: inline scripts, third-party code, and where its forms send data.
- CSP script safety checkWhether your Content-Security-Policy still lets injected inline scripts and eval() run, which undoes most of what CSP is for.
- CSP violation reporting checkWhether your Content-Security-Policy tells you when it blocks something, so an attack or a broken page does not go unnoticed.
- Subresource integrity checkWhether scripts your site loads from other companies' servers carry a fingerprint, so a tampered copy is refused.
- Third-party script checkHow many other companies' scripts your homepage runs. Each one can see what your visitors see and type.
- Form security checkWhether the forms on your homepage send what people type over an encrypted connection.
- Cookie prefix checkWhether your site's important cookies use the __Host- and __Secure- name prefixes that make browsers enforce their protections.
Domain Registration
Who holds your domain, how old it is, and how close it is to expiring.
- Domain expiration checkWhen your domain registration runs out. An expired domain takes your website and email down together.
- Domain age checkHow long ago the domain was registered. Very new domains are treated with more suspicion by spam filters.
- Registrar checkThe company your domain is registered with, and the account that controls everything else.
- Web host checkWhich company hosts your website, identified from the addresses your domain points to.
Reputation
Whether spam blocklists have flagged the servers behind your domain.
Attack surface
The subdomains the public can find, each one a door into your business.
Sensitive paths
Private files that should never be downloadable from your website.
Technology
What your website runs on, and whether it tells strangers more than it should.
Security maturity
The small published files that show you take security reports seriously.
