See your website the way everyone else can.
A careful, outside-only check of your domain's security configuration: HTTPS, certificates, email protection and DNS. It's explained in plain English, with the fixes written for whoever looks after your site.
33 of 34 checks completed
Medium www.example.com does not redirect HTTP to HTTPS
Visitors who type the address without https:// stay on an unencrypted connection, where their traffic can be read or changed.
What to do: Redirect every plain-HTTP request to the same address over HTTPS.
nginx
server {
listen 80;
server_name example.com www.example.com;
return 301 https://$host$request_uri;
}
Seven things anyone can see from outside
Every check looks only at what your domain shows the world. Open a card to see an example result.
-
Example result: Medium www.example.com does not redirect HTTP to HTTPS
-
Example result: Passed The certificate for example.com is valid for 196 more days
-
Example result: Medium example.com has no DMARC record
-
Example result: Low https://example.com/ has no Strict-Transport-Security header
-
Example result: Note DNSSEC is not enabled for example.com
-
Example result: Doesn't apply The homepage did not set any cookies.
-
Example result: Passed https://example.com/ is not a directory listing
-
Example result: Not checked DKIM can't generally be checked from the domain alone, because each signing key is published under a name (a selector) that only the sender knows. The analyser does not guess selectors.
Every problem comes with who fixes it
Findings are grouped by who acts, so you can forward the right part to your web host, DNS provider or email provider. Each finding includes the technical detail they'll need.
Open the full sample reportWhat to fix, and who fixes it
- Your web host or website developerwww.example.com does not redirect HTTP to HTTPS
- Your web host or website developerhttps://example.com/ has no Content-Security-Policy
- Your web host or website developerhttps://example.com/ has no Strict-Transport-Security header
- Your email providerexample.com has no DMARC record
Nothing for this provider in the example.
How the early access works
- Email us your domainJust the domain name, for example yourbusiness.com.au.
- Show it's yoursAdd one DNS record we send you. We only analyse domains their owners ask us to.
- Get your reportPlain English plus the technical detail. Free during early access, in return for your feedback.
What it is, and what it isn't
- Only your domain and its www address
- Ordinary web requests, like a visitor's browser makes
- Public DNS, email and domain registration records
- No port scanning, password guessing or break-in attempts
- Not a penetration test or vulnerability assessment
- Not proof that a website is secure
Ask for a free early analysis
Email us your domain. We'll reply with a DNS record to add, then send your report.
hello@seenfromoutside.com