Sample report: example.com is a demonstration domain and these results are illustrative.

Seen From Outside · Website Security Analyser

example.com

Also analysed: www.example.com

Analysed 28 Sep 2026, 01:00 UTC

84/100

Security Configuration Score

Based on the externally observable configuration checks performed, example.com scored 84/100.

33 of 34 checks completed

Most important

  1. www.example.com does not redirect HTTP to HTTPS
  2. example.com has no DMARC record
  3. https://example.com/ has no Content-Security-Policy

A passive, point-in-time check of external configuration. Not a penetration test or vulnerability assessment, and not proof that the website is secure.

Changes since the previous analysis

This is the first stored analysis of this domain, so there is nothing to compare against.

Important findings 4

Medium

www.example.com does not redirect HTTP to HTTPS

Visitors who type the address without https:// stay on an unencrypted connection, where their traffic can be read or changed.

Your web host or website developer

  • www.example.com
Medium

example.com has no DMARC record

Without DMARC, receivers have no domain-published instructions for handling mail that fails authentication, and the owner gets no reports of abuse.

Your email provider

  • example.com
Low

https://example.com/ has no Content-Security-Policy

Without a Content-Security-Policy, the browser has no extra limits on what scripts or resources the page can load if an injection flaw is ever found.

Your web host or website developer

  • example.com
Low

https://example.com/ has no Strict-Transport-Security header

Without HSTS, browsers only know to use HTTPS after visiting once, leaving the first visit (and any plain-HTTP link) open to interception.

Your web host or website developer

  • example.com

What to fix, and who fixes it

Your web host or website developer

  • Medium www.example.com does not redirect HTTP to HTTPS

    Redirect every plain-HTTP request to the same address over HTTPS.

    Applies to: www.example.com

    Configuration examples

    nginx

    server {
        listen 80;
        server_name example.com www.example.com;
        return 301 https://$host$request_uri;
    }

    Apache

    RewriteEngine On
    RewriteCond %{HTTPS} off
    RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

    Cloudflare

    SSL/TLS → Edge Certificates → Always Use HTTPS: On.
  • Low https://example.com/ has no Content-Security-Policy

    Start with a Content-Security-Policy in report-only mode, check the reports, then enforce it. Report-only violations only appear in the browser's developer console unless a report-to or report-uri endpoint is added to receive them. A good policy needs tailoring to the site; the example is a starting point, not a drop-in.

    Applies to: example.com

    Configuration examples

    nginx

    add_header Content-Security-Policy-Report-Only "default-src 'self'" always;

    Apache

    Header always set Content-Security-Policy-Report-Only "default-src 'self'"
  • Low https://example.com/ has no Strict-Transport-Security header

    Add the Strict-Transport-Security header with a max-age of at least six months (a year is common). Add includeSubDomains or preload only once every subdomain serves HTTPS.

    Applies to: example.com

    Configuration examples

    nginx

    add_header Strict-Transport-Security "max-age=31536000" always;

    Apache

    Header always set Strict-Transport-Security "max-age=31536000"

    Cloudflare

    SSL/TLS → Edge Certificates → HTTP Strict Transport Security (HSTS): enable, with a max-age of 12 months.

Your email provider

The records themselves are added at your DNS provider.

  • Medium example.com has no DMARC record

    Publish a DMARC record, starting at p=none while reports are reviewed.

    Applies to: example.com

    Configuration examples

    DNS record

    _dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:<reports address>"

Passed checks

HTTPS & redirects
HTTPS availability · No HTTPS to HTTP downgrade · Redirect behaviour · Mixed content
TLS & certificates
Certificate validity · Certificate name · Certificate trust · Outdated TLS versions · Modern TLS versions · TLS 1.3
Email domain
SPF record · SPF default policy · SPF validity
Security headers
X-Content-Type-Options · Clickjacking protection · Referrer-Policy · X-XSS-Protection
DNS
Stale DNS alias · Nameserver redundancy · www host · Public addresses · Domain registration expiry
Public configuration
Directory listing · Software version disclosure

Detailed results

HTTPS & redirects 80/100 · 4 passed · 1 issue
Passed

HTTPS availability both hosts

example.com serves HTTPS

Visitors can reach the site over an encrypted connection.

Evidence and how to fix

example.com

HTTP status
200
Final address
https://example.com/
HTTP version
not set

www.example.com

HTTP status
200
Final address
https://example.com/
HTTP version
not set
Medium

HTTP to HTTPS redirect

www.example.com does not redirect HTTP to HTTPS

Visitors who type the address without https:// stay on an unencrypted connection, where their traffic can be read or changed.

  • Passed example.com example.com redirects HTTP to HTTPS Visitors who type the plain address end up on HTTPS.
  • Medium www.example.com www.example.com does not redirect HTTP to HTTPS Visitors who type the address without https:// stay on an unencrypted connection, where their traffic can be read or changed.
Evidence and how to fix

example.com

Redirect chain
http://example.com/ → https://example.com/
Final address
https://example.com/
Redirects to another site
not set
Redirect result
followed

www.example.com

Redirect chain
none
Final address
http://www.example.com/
Redirects to another site
not set
Redirect result
none

How to fix: Redirect every plain-HTTP request to the same address over HTTPS.

nginx

server {
    listen 80;
    server_name example.com www.example.com;
    return 301 https://$host$request_uri;
}

Apache

RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

Cloudflare

SSL/TLS → Edge Certificates → Always Use HTTPS: On.
Passed

No HTTPS to HTTP downgrade both hosts

example.com never redirects from HTTPS to HTTP

No redirect takes visitors from HTTPS back to plain HTTP.

Passed

Redirect behaviour both hosts

example.com redirects cleanly

Redirects reach a final page in two steps or fewer.

Evidence and how to fix

example.com

Redirect chain
http://example.com/ → https://example.com/
Redirect result
followed
Redirects to another site
not set
Redirect hops
1

www.example.com

Redirect chain
none
Redirect result
none
Redirects to another site
not set
Redirect hops
0
Passed

Mixed content example.com

https://example.com/ loads everything over HTTPS

No plain-HTTP resources were found in the homepage.

Evidence and how to fix

example.com

Page
https://example.com/
Insecure resources
none
Examples
none
TLS & certificates 100/100 · 6 passed
Passed

Certificate validity both hosts

The certificate for example.com is valid for 196 more days

The HTTPS certificate is within its validity period.

Evidence and how to fix

example.com

Valid from
30 Jul 2026 (60 days ago)
Valid until
12 Apr 2027 (in 196 days)
Issuer
CN=Example Certificate Authority
Days left
196

www.example.com

Valid from
30 Jul 2026 (60 days ago)
Valid until
12 Apr 2027 (in 196 days)
Issuer
CN=Example Certificate Authority
Days left
196
Passed

Certificate name both hosts

The certificate for example.com matches the name

The certificate covers the name visitors use.

Passed

Certificate trust both hosts

The certificate on example.com is trusted

The certificate chains to a certificate authority browsers trust.

Evidence and how to fix

example.com

Issuer
CN=Example Certificate Authority
Trust problem
not set

www.example.com

Issuer
CN=Example Certificate Authority
Trust problem
not set
PassedMedium confidence

Outdated TLS versions both hosts

example.com does not accept TLS 1.0 or 1.1

TLS 1.0 and 1.1 were refused. A server that drops the connection is treated as refusing, so this result is slightly less certain.

Evidence and how to fix

example.com

TLS versions accepted
TLSv1.2, TLSv1.3
TLS versions not tested
none

www.example.com

TLS versions accepted
TLSv1.2, TLSv1.3
TLS versions not tested
none
Passed

Modern TLS versions both hosts

example.com supports TLS 1.2 or 1.3

Modern browsers can connect using a supported TLS version.

Evidence and how to fix

example.com

TLS versions accepted
TLSv1.2, TLSv1.3
TLS versions not tested
none

www.example.com

TLS versions accepted
TLSv1.2, TLSv1.3
TLS versions not tested
none
Passed

TLS 1.3 both hosts

example.com offers TLS 1.3

TLS 1.3 is available to visitors whose browsers support it.

Evidence and how to fix

example.com

TLS versions accepted
TLSv1.2, TLSv1.3
TLS versions not tested
none

www.example.com

TLS versions accepted
TLSv1.2, TLSv1.3
TLS versions not tested
none
Email domain 69/100 · 3 passed · 1 issue · 2 notes · 1 not checked · 3 don't apply
Passed

SPF record example.com

example.com has an SPF record

An SPF record tells receiving mail servers which services are authorised to send email for this domain.

Evidence and how to fix

example.com

SPF record
v=spf1 include:_spf.example-mail.net -all
Receives email (MX)
yes
Passed

SPF default policy example.com

example.com's SPF record ends in a restrictive all

The SPF record fails unauthorised senders (-all) or marks them as suspicious (~all).

Evidence and how to fix

example.com

SPF record
v=spf1 include:_spf.example-mail.net -all
SPF default
-
Passed

SPF validity example.com

example.com's SPF record is valid

The SPF record has one record, at most 10 DNS lookups and only recognised mechanisms.

Evidence and how to fix

example.com

SPF record
v=spf1 include:_spf.example-mail.net -all
SPF records
1
SPF DNS lookups
2
Unrecognised terms
none
Medium

DMARC record example.com

example.com has no DMARC record

Without DMARC, receivers have no domain-published instructions for handling mail that fails authentication, and the owner gets no reports of abuse.

Evidence and how to fix

example.com

DMARC record
not set
Receives email (MX)
yes

How to fix: Publish a DMARC record, starting at p=none while reports are reviewed.

DNS record

_dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:<reports address>"
Doesn't apply

DMARC policy example.com

No DMARC record was found.

Doesn't apply

DMARC coverage example.com

No DMARC record was found.

Doesn't apply

DMARC reporting example.com

No DMARC record was found.

Note

MTA-STS example.com

example.com does not publish MTA-STS

Without MTA-STS, incoming mail can be delivered over an unencrypted or unauthenticated connection without the sender being warned.

Note

TLS reporting example.com

example.com does not publish TLS-RPT

Without TLS-RPT, the owner gets no reports of failed TLS connections to incoming mail servers.

Not checked

DKIM example.com

DKIM can't generally be checked from the domain alone, because each signing key is published under a name (a selector) that only the sender knows. The analyser does not guess selectors.

Security headers 75/100 · 4 passed · 2 issues · 1 note
Low

Strict-Transport-Security example.com

https://example.com/ has no Strict-Transport-Security header

Without HSTS, browsers only know to use HTTPS after visiting once, leaving the first visit (and any plain-HTTP link) open to interception.

Evidence and how to fix

example.com

Page
https://example.com/
Header value
not set
max-age (seconds)
not set

How to fix: Add the Strict-Transport-Security header with a max-age of at least six months (a year is common). Add includeSubDomains or preload only once every subdomain serves HTTPS.

nginx

add_header Strict-Transport-Security "max-age=31536000" always;

Apache

Header always set Strict-Transport-Security "max-age=31536000"

Cloudflare

SSL/TLS → Edge Certificates → HTTP Strict Transport Security (HSTS): enable, with a max-age of 12 months.
Low

Content-Security-Policy example.com

https://example.com/ has no Content-Security-Policy

Without a Content-Security-Policy, the browser has no extra limits on what scripts or resources the page can load if an injection flaw is ever found.

Evidence and how to fix

example.com

Page
https://example.com/
Header value
not set
Report-only policy
no
Allows 'unsafe-inline'
no

How to fix: Start with a Content-Security-Policy in report-only mode, check the reports, then enforce it. Report-only violations only appear in the browser's developer console unless a report-to or report-uri endpoint is added to receive them. A good policy needs tailoring to the site; the example is a starting point, not a drop-in.

nginx

add_header Content-Security-Policy-Report-Only "default-src 'self'" always;

Apache

Header always set Content-Security-Policy-Report-Only "default-src 'self'"
Passed

X-Content-Type-Options example.com

https://example.com/ sets X-Content-Type-Options

Browsers are told not to guess a different content type.

Evidence and how to fix

example.com

Page
https://example.com/
Header value
nosniff
Passed

Clickjacking protection example.com

https://example.com/ is protected against clickjacking

The page tells browsers it must not be framed by another site.

Evidence and how to fix

example.com

Page
https://example.com/
X-Frame-Options
SAMEORIGIN
CSP frame-ancestors
no
Passed

Referrer-Policy example.com

https://example.com/ sets Referrer-Policy

The page controls how much of its URL is sent to other sites.

Evidence and how to fix

example.com

Page
https://example.com/
Header value
strict-origin-when-cross-origin
Note

Permissions-Policy example.com

https://example.com/ has no Permissions-Policy header

Without it, the page and anything embedded in it can use browser features (camera, microphone, geolocation, and more) without an extra restriction.

Evidence and how to fix

example.com

Page
https://example.com/
Header value
not set
Passed

X-XSS-Protection example.com

https://example.com/ does not enable the legacy X-XSS-Protection filter

The deprecated browser XSS filter is left off, avoiding the bugs it introduced in some browsers.

Evidence and how to fix

example.com

Page
https://example.com/
Header value
not set
DNS 100/100 · 5 passed · 2 notes
Passed

Stale DNS alias both hosts

example.com has no dangling CNAME

The host has no CNAME record, or its target resolves normally.

Evidence and how to fix

example.com

Host
example.com
Alias target
not set
Target does not exist
no

www.example.com

Host
www.example.com
Alias target
not set
Target does not exist
no
Passed

Nameserver redundancy example.com

example.com has redundant nameservers

Two or more nameservers are listed, so the domain keeps resolving if one fails.

Evidence and how to fix

example.com

Nameservers
ns1.example-dns.net, ns2.example-dns.net
Note

DNSSEC example.com

DNSSEC is not enabled for example.com

DNSSEC lets resolvers verify DNS answers were not forged. It is optional; ask your DNS provider whether they support it.

Evidence and how to fix

example.com

DS records
0
DNSKEY records
0
Note

CAA records example.com

example.com has no CAA records

Without CAA records, any certificate authority can issue a certificate for this domain.

Evidence and how to fix

example.com

Records
none

DNS record

example.com. CAA 0 issue "<your certificate authority, e.g. letsencrypt.org>"
Passed

www host www.example.com

www.example.com resolves

Visitors who type www. reach the site.

Evidence and how to fix

www.example.com

Host
www.example.com
Passed

Public addresses both hosts

example.com resolves only to public addresses

The name resolves only to publicly routable addresses.

Evidence and how to fix

example.com

Host
example.com

www.example.com

Host
www.example.com
Passed

Domain registration expiry example.com

example.com's registration is not expiring soon

The domain is registered for more than 30 days.

Evidence and how to fix

example.com

Registration expires
25 Jul 2027 (in 300 days)
Days left
300
Registrar
Example Registrar
Cookies Not applicable · 3 don't apply
Doesn't apply

Cookie Secure flag example.com

The homepage did not set any cookies.

Doesn't apply

Cookie HttpOnly flag example.com

The homepage did not set any cookies.

Doesn't apply

Cookie SameSite attribute example.com

The homepage did not set any cookies.

Public configuration 100/100 · 2 passed
Passed

Directory listing example.com

https://example.com/ is not a directory listing

The homepage does not match a standard directory-index layout.

Evidence and how to fix

example.com

Page
https://example.com/
Listing layout
not set
Passed

Software version disclosure example.com

https://example.com/ does not reveal a software version

Neither the Server nor the X-Powered-By header includes a version number.

Evidence and how to fix

example.com

Page
https://example.com/
Server header
nginx
X-Powered-By header
not set

About this analysis

Scope

Methodology

Hosts analysed
example.com, www.example.com
Categories checked
HTTPS & redirects, TLS & certificates, Email domain, Security headers, DNS, Cookies, Public configuration
HTTP requests
6
TLS handshakes
12
DNS queries
26
Registry lookups
1
Checks
33 completed, 1 not completed
Per host
example.com
32 of 33 results completed
www.example.com
13 of 13 results completed

DNSSEC is judged from the presence of DS records at the parent zone and DNSKEY records at the domain. Signatures are not validated, and the DS record is not matched against the keys.

Limitations

This is a passive, point-in-time analysis of the domain's external security configuration, limited to the checks listed in this report. It is not a penetration test, a vulnerability assessment or a security certification, and it is not proof that the website is secure.