Trouble signing in
Forgot your password
Request a reset link. It is single-use and expires in 60 minutes.
Locked out
Six wrong attempts locks the account for 30 minutes. It clears on its own — no need to call.
If the account stays locked or something is broken, send the details directly to our support inbox.
Or call (330) 305-2750.
What the NHM dashboard is
The free tools on this site — the IT checkup, domain checkup, password checker, phishing quiz — run without an account and give you a one-time result. The dashboard runs the same checks across every domain you track, on a schedule, and tells you when something changes.
No account yet? Create a free one — the free tier covers daily manual scans. Or take the dashboard tour first.
What the dashboard covers
Twelve of the panels an account unlocks. The full list is on the dashboard tour; new panels ship regularly.
Scanner
Multi-step domain security scan across DNS, SSL, and configuration.
SSL Certificates
Certificate status and expiry for every domain, with notice before they lapse.
DMARC Reports
Aggregate DMARC reports, surfacing senders that are misaligned or spoofing you.
Vulnerability Scan
Open ports, outdated software, and known CVEs across watched systems.
Security Posture
Roll-up grade of DNS, email authentication, headers, and exposed surface.
Compliance
Evidence pack for PCI, HIPAA, and cyber-insurance renewals.
Uptime
Five-minute probes that surface incidents before customers notice.
Email Score
SPF, DKIM, DMARC, MX, and forwarding posture, graded.
Tech Stack
Server, framework, CDN, and analytics detected per site.
Blacklist
Your domains and sending IPs against the blocklists providers use.
HTTP Headers
CSP, HSTS, X-Frame-Options, and Permissions-Policy with fixes.
Attack Surface
Ports, subdomains, exposed services, certificate transparency.
How login security works
Passwords are salted and hashed server-side; we cannot read them in the clear. The session cookie is HttpOnly, Secure, and SameSite=Strict, so the browser does not expose it to scripts and does not send it when you arrive from another site. Sessions expire after 24 hours of inactivity, admin accounts included.
Two-factor authentication is supported. With it enabled, the password step is followed by a six-digit code from your authenticator app. Turn it on from the Account panel once you are signed in.
Failed logins are rate-limited: six wrong attempts against the same account or from the same IP within 30 minutes locks it for 30 minutes. The reset form gives the same confirmation whether or not an address has an account, so it cannot be used to work out who is a customer.
