What Is a Website Security Scan and What Does It Check?
Learn what an external website security scan can identify, what it cannot guarantee and how to use its findings responsibly.
Read articleUnderstand website security findings, improve public configurations and give developers clear steps for fixing DNS, SSL, email, browser and server-exposure problems.
Clear technical explanations written for website owners, developers, agencies and teams responsible for public websites.
Learn what an external website security scan can identify, what it cannot guarantee and how to use its findings responsibly.
Read articleUnderstand A, AAAA, CNAME, NS, SOA, MX, TXT, CAA and DNSSEC records and why their configuration matters.
Read articleLearn how certificate trust, hostname matching, expiration, issuer and chain configuration affect HTTPS security.
Read articleLearn how SPF and DMARC policies reduce domain spoofing and why monitoring-only policies provide limited enforcement.
Read articleUnderstand the browser security headers that reduce script injection, clickjacking, MIME confusion and information leakage.
Read articleLearn what the Secure, HttpOnly and SameSite cookie attributes do and how weak cookie settings can increase risk.
Read articleLearn how Server and X-Powered-By headers reveal public technology details and when that disclosure should be reduced.
Read articleUnderstand the risks of publicly exposed environment files, repositories, database backups, archives and application logs.
Read article