Loading...

Trouble signing in

Forgot your password

Request a reset link. It is single-use and expires in 60 minutes.

Locked out

Six wrong attempts locks the account for 30 minutes. It clears on its own — no need to call.

If the account stays locked or something is broken, send the details directly to our support inbox.

Or call (330) 305-2750.

What the NHM dashboard is

The free tools on this site — the IT checkup, domain checkup, password checker, phishing quiz — run without an account and give you a one-time result. The dashboard runs the same checks across every domain you track, on a schedule, and tells you when something changes.

No account yet? Create a free one — the free tier covers daily manual scans. Or take the dashboard tour first.

What the dashboard covers

Twelve of the panels an account unlocks. The full list is on the dashboard tour; new panels ship regularly.

Scanner

Multi-step domain security scan across DNS, SSL, and configuration.

SSL Certificates

Certificate status and expiry for every domain, with notice before they lapse.

DMARC Reports

Aggregate DMARC reports, surfacing senders that are misaligned or spoofing you.

Vulnerability Scan

Open ports, outdated software, and known CVEs across watched systems.

Security Posture

Roll-up grade of DNS, email authentication, headers, and exposed surface.

Compliance

Evidence pack for PCI, HIPAA, and cyber-insurance renewals.

Uptime

Five-minute probes that surface incidents before customers notice.

Email Score

SPF, DKIM, DMARC, MX, and forwarding posture, graded.

Tech Stack

Server, framework, CDN, and analytics detected per site.

Blacklist

Your domains and sending IPs against the blocklists providers use.

HTTP Headers

CSP, HSTS, X-Frame-Options, and Permissions-Policy with fixes.

Attack Surface

Ports, subdomains, exposed services, certificate transparency.

How login security works

Passwords are salted and hashed server-side; we cannot read them in the clear. The session cookie is HttpOnly, Secure, and SameSite=Strict, so the browser does not expose it to scripts and does not send it when you arrive from another site. Sessions expire after 24 hours of inactivity, admin accounts included.

Two-factor authentication is supported. With it enabled, the password step is followed by a six-digit code from your authenticator app. Turn it on from the Account panel once you are signed in.

Failed logins are rate-limited: six wrong attempts against the same account or from the same IP within 30 minutes locks it for 30 minutes. The reset form gives the same confirmation whether or not an address has an account, so it cannot be used to work out who is a customer.