Security Snapshot: [your-domain].com

Generated: 2026-03-28 14:17:43 UTC — Sample Report

⚠ Risk Level: MEDIUM
Risk Score: 25 / 100
Overall risk: MEDIUM. Findings: 1 MEDIUM, 4 LOW, 3 INFO.
Scope & Limitations: This report reflects external observations only. It does not assess internal systems, application code, authentication mechanisms, or infrastructure configuration. Findings are based on publicly observable signals at the time of scan. DKIM detection is best-effort only — a negative result does not confirm DKIM is absent. WHOIS data accuracy depends on registrar cooperation. Port checks use short timeouts and may miss firewalled services.

Key Findings

MEDIUM DMARC record missing

No DMARC record found. Without DMARC, email receivers cannot take action on SPF/DKIM failures, making domain spoofing easier.

LOW Missing security header: Strict-Transport-Security

Enforces HTTPS connections and prevents SSL stripping attacks.

LOW Missing security header: Content-Security-Policy

Mitigates cross-site scripting and data injection attacks.

LOW Missing security header: X-Frame-Options

Prevents clickjacking by controlling iframe embedding.

LOW Missing security header: X-Content-Type-Options

Prevents browsers from MIME-sniffing the content type.

Observations

Informational observations do not affect the risk score. They reflect scan limitations, infrastructure notes, and other non-actionable signals.

INFO Missing security header: Referrer-Policy

Controls how much referrer information is included with requests.

INFO Missing security header: Permissions-Policy

Controls browser feature access (camera, microphone, geolocation, etc.).

INFO Email provider: Google Workspace detected

MX records indicate that Google Workspace handles email for this domain. This is an informational observation.

Recommendations

  1. Publish a DMARC record: _dmarc.[your-domain].com TXT "v=DMARC1; p=reject; rua=mailto:dmarc@[your-domain].com"
  2. Add: Strict-Transport-Security: max-age=31536000; includeSubDomains
  3. Define a Content-Security-Policy appropriate for your application.
  4. Add: X-Frame-Options: DENY or SAMEORIGIN
  5. Add: X-Content-Type-Options: nosniff
  6. Add: Referrer-Policy: strict-origin-when-cross-origin
  7. Add a Permissions-Policy header to restrict unnecessary browser APIs.

Positive Signals

SPF record is present
Valid TLS certificate installed
TLS 1.3 supported
Certificate hostname matches domain

Email Security

SPF RecordPASSv=spf1 include:_spf.google.com ~all
DMARC RecordFAILDMARC record not found
DMARC PolicyN/A
DKIM DetectedPASSgoogle
DKIM NoteDKIM selector names are not publicly enumerable. A negative result here does not confirm DKIM is absent.

TLS / Certificate

ConnectedPASS
IssuerLet's Encrypt
Subject (CN)[your-domain].com
Expires2026-09-15 00:00:00+00:00
Days Remaining171 days
Hostname MatchPASS
TLS VersionTLSv1.3

Security Headers

URL Checkedhttps://[your-domain].com
Strict-Transport-SecurityFAILmissing
Content-Security-PolicyFAILmissing
X-Frame-OptionsFAILmissing
X-Content-Type-OptionsFAILmissing
Referrer-PolicyFAILmissing
Permissions-PolicyFAILmissing

Port Exposure

Port 80 (HTTP)OPENUnencrypted web traffic
Port 443 (HTTPS)OPENEncrypted web traffic
Port 25 (SMTP)CLOSEDDirect mail relay — often blocked by ISPs
Port 465 (SMTPS)CLOSEDEncrypted SMTP submission
Port 587 (SMTP/STARTTLS)CLOSEDModern authenticated mail submission
Port 8080 (HTTP-alt)CLOSEDCommon alternate web port
Port 8443 (HTTPS-alt)CLOSEDCommon alternate HTTPS port

DNS Health

A Records203.0.113.42, 203.0.113.91
AAAA Recordsnone
MX Records10 aspmx.l.google.com., 20 alt1.aspmx.l.google.com., 30 alt2.aspmx.l.google.com.
Nameserversns1.example-registrar.com., ns2.example-registrar.com.

WHOIS / Domain Info

RegistrarNamecheap, Inc.
Created2018-05-14
Expires2027-05-14
Domain Age2875 days