www.example.com does not redirect HTTP to HTTPS
Visitors who type the address without https:// stay on an unencrypted connection, where their traffic can be read or changed.
- www.example.com
Sample report: example.com is a demonstration domain and these results are illustrative.
Seen From Outside · Website Security Analyser
Based on the externally observable configuration checks performed, example.com scored 84/100.
33 of 34 checks completed
A passive, point-in-time check of external configuration. Not a penetration test or vulnerability assessment, and not proof that the website is secure.
This is the first stored analysis of this domain, so there is nothing to compare against.
Visitors who type the address without https:// stay on an unencrypted connection, where their traffic can be read or changed.
Without DMARC, receivers have no domain-published instructions for handling mail that fails authentication, and the owner gets no reports of abuse.
Without a Content-Security-Policy, the browser has no extra limits on what scripts or resources the page can load if an injection flaw is ever found.
Without HSTS, browsers only know to use HTTPS after visiting once, leaving the first visit (and any plain-HTTP link) open to interception.
Redirect every plain-HTTP request to the same address over HTTPS.
nginx
server {
listen 80;
server_name example.com www.example.com;
return 301 https://$host$request_uri;
}Apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]Cloudflare
SSL/TLS → Edge Certificates → Always Use HTTPS: On.
Start with a Content-Security-Policy in report-only mode, check the reports, then enforce it. Report-only violations only appear in the browser's developer console unless a report-to or report-uri endpoint is added to receive them. A good policy needs tailoring to the site; the example is a starting point, not a drop-in.
nginx
add_header Content-Security-Policy-Report-Only "default-src 'self'" always;
Apache
Header always set Content-Security-Policy-Report-Only "default-src 'self'"
Add the Strict-Transport-Security header with a max-age of at least six months (a year is common). Add includeSubDomains or preload only once every subdomain serves HTTPS.
nginx
add_header Strict-Transport-Security "max-age=31536000" always;
Apache
Header always set Strict-Transport-Security "max-age=31536000"
Cloudflare
SSL/TLS → Edge Certificates → HTTP Strict Transport Security (HSTS): enable, with a max-age of 12 months.
The records themselves are added at your DNS provider.
Publish a DMARC record, starting at p=none while reports are reviewed.
DNS record
_dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:<reports address>"
HTTPS availability both hosts
example.com serves HTTPS
Visitors can reach the site over an encrypted connection.
example.com
www.example.com
HTTP to HTTPS redirect
www.example.com does not redirect HTTP to HTTPS
Visitors who type the address without https:// stay on an unencrypted connection, where their traffic can be read or changed.
example.com
www.example.com
How to fix: Redirect every plain-HTTP request to the same address over HTTPS.
nginx
server {
listen 80;
server_name example.com www.example.com;
return 301 https://$host$request_uri;
}Apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]Cloudflare
SSL/TLS → Edge Certificates → Always Use HTTPS: On.
No HTTPS to HTTP downgrade both hosts
example.com never redirects from HTTPS to HTTP
No redirect takes visitors from HTTPS back to plain HTTP.
Redirect behaviour both hosts
example.com redirects cleanly
Redirects reach a final page in two steps or fewer.
example.com
www.example.com
Mixed content example.com
https://example.com/ loads everything over HTTPS
No plain-HTTP resources were found in the homepage.
example.com
Certificate validity both hosts
The certificate for example.com is valid for 196 more days
The HTTPS certificate is within its validity period.
example.com
www.example.com
Certificate name both hosts
The certificate for example.com matches the name
The certificate covers the name visitors use.
Certificate trust both hosts
The certificate on example.com is trusted
The certificate chains to a certificate authority browsers trust.
example.com
www.example.com
Outdated TLS versions both hosts
example.com does not accept TLS 1.0 or 1.1
TLS 1.0 and 1.1 were refused. A server that drops the connection is treated as refusing, so this result is slightly less certain.
example.com
www.example.com
Modern TLS versions both hosts
example.com supports TLS 1.2 or 1.3
Modern browsers can connect using a supported TLS version.
example.com
www.example.com
TLS 1.3 both hosts
example.com offers TLS 1.3
TLS 1.3 is available to visitors whose browsers support it.
example.com
www.example.com
SPF record example.com
example.com has an SPF record
An SPF record tells receiving mail servers which services are authorised to send email for this domain.
example.com
SPF default policy example.com
example.com's SPF record ends in a restrictive all
The SPF record fails unauthorised senders (-all) or marks them as suspicious (~all).
example.com
SPF validity example.com
example.com's SPF record is valid
The SPF record has one record, at most 10 DNS lookups and only recognised mechanisms.
example.com
DMARC record example.com
example.com has no DMARC record
Without DMARC, receivers have no domain-published instructions for handling mail that fails authentication, and the owner gets no reports of abuse.
example.com
How to fix: Publish a DMARC record, starting at p=none while reports are reviewed.
DNS record
_dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:<reports address>"
DMARC policy example.com
No DMARC record was found.
DMARC coverage example.com
No DMARC record was found.
DMARC reporting example.com
No DMARC record was found.
MTA-STS example.com
example.com does not publish MTA-STS
Without MTA-STS, incoming mail can be delivered over an unencrypted or unauthenticated connection without the sender being warned.
TLS reporting example.com
example.com does not publish TLS-RPT
Without TLS-RPT, the owner gets no reports of failed TLS connections to incoming mail servers.
DKIM example.com
DKIM can't generally be checked from the domain alone, because each signing key is published under a name (a selector) that only the sender knows. The analyser does not guess selectors.
Strict-Transport-Security example.com
https://example.com/ has no Strict-Transport-Security header
Without HSTS, browsers only know to use HTTPS after visiting once, leaving the first visit (and any plain-HTTP link) open to interception.
example.com
How to fix: Add the Strict-Transport-Security header with a max-age of at least six months (a year is common). Add includeSubDomains or preload only once every subdomain serves HTTPS.
nginx
add_header Strict-Transport-Security "max-age=31536000" always;
Apache
Header always set Strict-Transport-Security "max-age=31536000"
Cloudflare
SSL/TLS → Edge Certificates → HTTP Strict Transport Security (HSTS): enable, with a max-age of 12 months.
Content-Security-Policy example.com
https://example.com/ has no Content-Security-Policy
Without a Content-Security-Policy, the browser has no extra limits on what scripts or resources the page can load if an injection flaw is ever found.
example.com
How to fix: Start with a Content-Security-Policy in report-only mode, check the reports, then enforce it. Report-only violations only appear in the browser's developer console unless a report-to or report-uri endpoint is added to receive them. A good policy needs tailoring to the site; the example is a starting point, not a drop-in.
nginx
add_header Content-Security-Policy-Report-Only "default-src 'self'" always;
Apache
Header always set Content-Security-Policy-Report-Only "default-src 'self'"
X-Content-Type-Options example.com
https://example.com/ sets X-Content-Type-Options
Browsers are told not to guess a different content type.
example.com
Clickjacking protection example.com
https://example.com/ is protected against clickjacking
The page tells browsers it must not be framed by another site.
example.com
Referrer-Policy example.com
https://example.com/ sets Referrer-Policy
The page controls how much of its URL is sent to other sites.
example.com
Permissions-Policy example.com
https://example.com/ has no Permissions-Policy header
Without it, the page and anything embedded in it can use browser features (camera, microphone, geolocation, and more) without an extra restriction.
example.com
X-XSS-Protection example.com
https://example.com/ does not enable the legacy X-XSS-Protection filter
The deprecated browser XSS filter is left off, avoiding the bugs it introduced in some browsers.
example.com
Stale DNS alias both hosts
example.com has no dangling CNAME
The host has no CNAME record, or its target resolves normally.
example.com
www.example.com
Nameserver redundancy example.com
example.com has redundant nameservers
Two or more nameservers are listed, so the domain keeps resolving if one fails.
example.com
DNSSEC example.com
DNSSEC is not enabled for example.com
DNSSEC lets resolvers verify DNS answers were not forged. It is optional; ask your DNS provider whether they support it.
example.com
CAA records example.com
example.com has no CAA records
Without CAA records, any certificate authority can issue a certificate for this domain.
example.com
DNS record
example.com. CAA 0 issue "<your certificate authority, e.g. letsencrypt.org>"
www host www.example.com
www.example.com resolves
Visitors who type www. reach the site.
www.example.com
Public addresses both hosts
example.com resolves only to public addresses
The name resolves only to publicly routable addresses.
example.com
www.example.com
Domain registration expiry example.com
example.com's registration is not expiring soon
The domain is registered for more than 30 days.
example.com
Cookie Secure flag example.com
The homepage did not set any cookies.
Cookie HttpOnly flag example.com
The homepage did not set any cookies.
Cookie SameSite attribute example.com
The homepage did not set any cookies.
Directory listing example.com
https://example.com/ is not a directory listing
The homepage does not match a standard directory-index layout.
example.com
Software version disclosure example.com
https://example.com/ does not reveal a software version
Neither the Server nor the X-Powered-By header includes a version number.
example.com
DNSSEC is judged from the presence of DS records at the parent zone and DNSKEY records at the domain. Signatures are not validated, and the DS record is not matched against the keys.
This is a passive, point-in-time analysis of the domain's external security configuration, limited to the checks listed in this report. It is not a penetration test, a vulnerability assessment or a security certification, and it is not proof that the website is secure.