Sensitive paths

Exposed files check

Files such as .env, .git and backups hold passwords and source code. They should never be downloadable from your website.

Check this on your own domain now. It is free with a DomainGuard account, reads only public records, and gives you a report you can send to whoever runs your website.

What we look at

On domains with proof of ownership, we request about 100 well-known private paths (environment files, Git folders, CI configuration, database backups, debug pages) and check whether any answer with real content.

Why it matters to your business

An exposed .env or backup file can contain database passwords, API keys and email credentials, and automated bots look for them on every website every day. This is one of the most common ways small business sites are breached.

How to fix it

  1. Delete the files from the web root; they should never be deployed there.
  2. Block the paths at your CDN or server (deny /.env, /.git and backup extensions).
  3. Change every password and key the files contained, and assume they were already copied.

If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.

Keep an eye on it

A one-off check tells you how things stand today. On Starter and up, DomainGuard re-checks the domains it watches every day and alerts you in the app when something important changes, so you hear about it before a customer does.