Blog
Contact
Sign in
Scan complete
D
61/100
hola.com
Improved · F → D · +15
Compare
2 critical issues need immediate attention.
16/16
checks
47
passed
finished
Scan timestamps
Created
Aug 11, 2026, 10:13 PM
Started
Aug 11, 2026, 10:13 PM
Finished
Aug 11, 2026, 10:14 PM
Updated
Aug 11, 2026, 10:13 PM
Export PDF
Re-scan
Findings by severity
66 results
2
Critical
4
High
9
Medium
4
Low
47
Pass
Report coverage
98.53%
29 skipped - these limit completeness.
29 skipped
All
95
Critical
2
High
4
Medium
9
Low
4
Pass
47
Skipped
29
Email
96%
Sender Authentication (SPF)
Learn how it works
Info
6/7 pass
Sender Authentication (SPF)
SPF policy does not use strict fail mode
The SPF policy does not fully reject unauthorized senders.
Medium
Domain Alignment (DMARC)
Learn how it works
Info
4/7 pass
Domain Alignment (DMARC)
DMARC policy quarantines unauthenticated mail
The DMARC policy asks receivers to treat failing mail as suspicious, but does not request full rejection.
Medium
Domain Alignment (DMARC)
DMARC subdomain policy uses quarantine
Subdomains are protected by quarantine, but failing mail is not explicitly rejected.
Medium
Domain Alignment (DMARC)
DMARC alignment is relaxed
The DMARC record allows relaxed identifier alignment for DKIM or SPF.
Low
Certificate Binding (DANE)
Learn how it works
Info
1/5 pass
Certificate Binding (DANE)
No MX host TLSA zone is protected by DNSSEC
None of the MX hosts have DNSSEC on their TLSA lookup zones. DANE SMTP cannot function without DNSSEC, as sending servers will ignore TLSA records from unsigned zones.
Critical
Transport Policy (MTA-STS)
Learn how it works
Info
1/6 pass
Transport Policy (MTA-STS)
MTA-STS DNS record is missing
The domain does not publish an MTA-STS TXT record, so sending servers cannot discover or enforce an MTA-STS policy.
High
TLS Reporting (TLS-RPT)
Learn how it works
Info
1/4 pass
TLS Reporting (TLS-RPT)
No TLS-RPT record found
The domain does not publish a TLS-RPT record. Sending servers cannot report TLS errors to this domain.
High
DNS
100%
DNS Integrity (DNSSEC)
Learn how it works
Info
0/7 pass
DNS Integrity (DNSSEC)
DNSSEC is not enabled
The parent zone does not publish a DS record for this domain.
Medium
DNS Health (Delegation & Exposure)
Learn how it works
Info
7/8 pass
DNS Health (Delegation & Exposure)
SOA serial does not use the recommended format
The SOA record is otherwise valid, but the serial number does not follow the recommended YYYYMMDDnn date format.
Low
CAA and Certificate Issuance Surface
Learn how it works
Info
0/6 pass
CAA and Certificate Issuance Surface
No CAA record is published
The domain does not publish a CAA record, so any publicly trusted certificate authority may issue certificates for it after standard validation.
Low
CAA and Certificate Issuance Surface
Dangling _acme-challenge delegation
The _acme-challenge name delegates ACME validation to a target that no longer resolves, so an attacker who claims that target could obtain a trusted certificate for this domain.
Critical
TLS
100%
TLS Configuration
Learn how it works
Info
2/6 pass
TLS Configuration
Deprecated TLS version accepted (TLS 1.0 / TLS 1.1)
The server accepts TLS 1.0 and/or TLS 1.1, both formally deprecated by RFC 8996. These versions lack support for modern authenticated encryption and are the underlying cause of several named attacks (e.g. BEAST against TLS 1.0 CBC ciphers).
High
TLS Configuration
Legacy cipher suites accepted (3DES / CBC in TLS 1.0)
The server accepts cipher suites weakened by the 64-bit block size of 3DES (SWEET32, CVE-2016-2183) and/or CBC-mode ciphers in TLS 1.0 (contributing factor to BEAST). Exploitation requires specific conditions (e.g. very large data transfers for SWEET32).
Medium
TLS Configuration
Cipher suites without forward secrecy accepted
The server accepts one or more cipher suites using static RSA or static (EC)DH key exchange. If the server's private key is ever compromised, an attacker with recorded traffic can decrypt past sessions negotiated with these cipher suites.
Medium
Web
100%
Disclosure Policy (security.txt)
Learn how it works
Info
0/4 pass
Disclosure Policy (security.txt)
security.txt is not present or not usable
The domain does not publish a usable security.txt file. Either both /.well-known/security.txt and /security.txt returned no file (404/401/403/410), or the location responded with HTTP 200 but non-text/plain content (typically an application page) or a body that is not valid UTF-8.
Medium
HTTP Security Headers
Learn how it works
Info
3/7 pass
HTTP Security Headers
Content-Security-Policy is weak and bypass-prone
The CSP allows inline script execution without a nonce or hash, a wildcard or http:/data: script source, or does not restrict script sources at all. Such policies are commonly reported as bypassable in independent CSP research.
High
HTTP Security Headers
Referrer-Policy is not declared
The site does not send a Referrer-Policy header. Modern browsers default to a reasonably safe behavior, but the site does not explicitly guarantee it.
Medium
HTTP Security Headers
Permissions-Policy is missing or ineffective
The site either does not send a Permissions-Policy header, or the header only lists directives with a wildcard allowlist that does not restrict anything.
Medium
HTTP Security Headers
Deprecated security headers are present
The response sends one or more deprecated headers (X-XSS-Protection, Expect-CT, or Public-Key-Pins) that modern browsers ignore or that carry their own operational risk (HPKP).
Low
Feedback