Security Snapshot: [your-domain].com

Generated: 2026-03-28 09:44:11 UTC — Sample Report

✓ Risk Level: LOW
Risk Score: 8 / 100
Overall risk: LOW. Findings: 0 HIGH, 0 MEDIUM, 1 LOW, 2 INFO. Strong baseline configuration.
Good news: This domain is well-configured. The findings below are minor and do not represent immediate risk. The recommendations section includes optional improvements.
Scope & Limitations: This report reflects external observations only. It does not assess internal systems, application code, authentication mechanisms, or infrastructure configuration. Findings are based on publicly observable signals at the time of scan. DKIM detection is best-effort only — a negative result does not confirm DKIM is absent. WHOIS data accuracy depends on registrar cooperation. Port checks use short timeouts and may miss firewalled services.

Key Findings

LOW DMARC policy set to quarantine, not reject

DMARC is present and active. The current policy (p=quarantine) routes suspicious emails to spam rather than rejecting them outright. Tightening to p=reject would provide stronger protection.

Observations

Informational observations do not affect the risk score.

INFO Missing security header: Permissions-Policy

Controls browser feature access (camera, microphone, geolocation, etc.). Low priority for a primarily static site.

INFO Email provider: Google Workspace detected

MX records indicate that Google Workspace handles email for this domain. This is an informational observation.

Recommendations

  1. Consider tightening DMARC policy from p=quarantine to p=reject once you have confirmed legitimate mail is flowing correctly.
  2. Optionally add a Permissions-Policy header to restrict unnecessary browser APIs.

Positive Signals

SPF record is present and strict (-all)
DMARC record is present
Valid TLS certificate installed
TLS 1.3 supported
Certificate hostname matches domain
Certificate valid for 9+ months
Strict-Transport-Security header present
X-Frame-Options header present
X-Content-Type-Options header present
No unexpected ports open

Email Security

SPF RecordPASSv=spf1 include:_spf.google.com -all
DMARC RecordPASSv=DMARC1; p=quarantine; rua=mailto:dmarc@[your-domain].com
DMARC Policyquarantine
DKIM DetectedPASSgoogle
DKIM NoteDKIM selector names are not publicly enumerable. A negative result here does not confirm DKIM is absent.

TLS / Certificate

ConnectedPASS
IssuerLet's Encrypt
Subject (CN)[your-domain].com
Expires2026-12-18 00:00:00+00:00
Days Remaining265 days
Hostname MatchPASS
TLS VersionTLSv1.3

Security Headers

URL Checkedhttps://[your-domain].com
Strict-Transport-SecurityPASSmax-age=31536000; includeSubDomains
Content-Security-PolicyPASSpresent
X-Frame-OptionsPASSSAMEORIGIN
X-Content-Type-OptionsPASSnosniff
Referrer-PolicyPASSstrict-origin-when-cross-origin
Permissions-PolicyFAILmissing

Port Exposure

Port 80 (HTTP)OPENRedirects to HTTPS — expected
Port 443 (HTTPS)OPENEncrypted web traffic
Port 25 (SMTP)CLOSEDDirect mail relay — often blocked by ISPs
Port 465 (SMTPS)CLOSEDEncrypted SMTP submission
Port 587 (SMTP/STARTTLS)CLOSEDModern authenticated mail submission
Port 8080 (HTTP-alt)CLOSEDCommon alternate web port
Port 8443 (HTTPS-alt)CLOSEDCommon alternate HTTPS port

DNS Health

A Records203.0.113.15
AAAA Recordsnone
MX Records10 aspmx.l.google.com., 20 alt1.aspmx.l.google.com., 30 alt2.aspmx.l.google.com.
Nameserversns1.example-registrar.com., ns2.example-registrar.com.

WHOIS / Domain Info

RegistrarSquarespace Domains
Created2021-02-09
Expires2027-02-09
Domain Age1873 days