Blog
Contact
Sign in
Scan complete
C
78/100
mddv.pl
Improved · D → C · +11
Compare
1 critical issue needs immediate attention.
16/16
checks
62
passed
finished
Scan timestamps
Created
Jul 17, 2026, 5:05 AM
Started
Jul 17, 2026, 5:05 AM
Finished
Jul 17, 2026, 5:05 AM
Updated
Jul 17, 2026, 5:05 AM
Export PDF
Re-scan
Findings by severity
76 results
1
Critical
5
High
4
Medium
4
Low
62
Pass
Report coverage
98.52%
19 skipped - these limit completeness.
19 skipped
All
95
Critical
1
High
5
Medium
4
Low
4
Pass
62
Skipped
19
Email
96%
Domain Alignment (DMARC)
Learn how it works
Info
4/7 pass
Domain Alignment (DMARC)
DMARC policy quarantines unauthenticated mail
The DMARC policy asks receivers to treat failing mail as suspicious, but does not request full rejection.
Medium
Domain Alignment (DMARC)
DMARC subdomain policy uses quarantine
Subdomains are protected by quarantine, but failing mail is not explicitly rejected.
Medium
Domain Alignment (DMARC)
DMARC alignment is relaxed
The DMARC record allows relaxed identifier alignment for DKIM or SPF.
Low
Certificate Binding (DANE)
Learn how it works
Info
1/5 pass
Certificate Binding (DANE)
No MX host TLSA zone is protected by DNSSEC
None of the MX hosts have DNSSEC on their TLSA lookup zones. DANE SMTP cannot function without DNSSEC, as sending servers will ignore TLSA records from unsigned zones.
Critical
Transport Policy (MTA-STS)
Learn how it works
Info
1/6 pass
Transport Policy (MTA-STS)
MTA-STS DNS record is missing
The domain does not publish an MTA-STS TXT record, so sending servers cannot discover or enforce an MTA-STS policy.
High
TLS Reporting (TLS-RPT)
Learn how it works
Info
1/4 pass
TLS Reporting (TLS-RPT)
No TLS-RPT record found
The domain does not publish a TLS-RPT record. Sending servers cannot report TLS errors to this domain.
High
DNS
100%
DNS Health (Delegation & Exposure)
Learn how it works
Info
7/8 pass
DNS Health (Delegation & Exposure)
SOA serial does not use the recommended format
The SOA record is otherwise valid, but the serial number does not follow the recommended YYYYMMDDnn date format.
Low
CAA and Certificate Issuance Surface
Learn how it works
Info
1/6 pass
CAA and Certificate Issuance Surface
No CAA record is published
The domain does not publish a CAA record, so any publicly trusted certificate authority may issue certificates for it after standard validation.
Low
TLS
100%
TLS Configuration
Learn how it works
Info
4/6 pass
TLS Configuration
Cipher suites without forward secrecy accepted
The server accepts one or more cipher suites using static RSA or static (EC)DH key exchange. If the server's private key is ever compromised, an attacker with recorded traffic can decrypt past sessions negotiated with these cipher suites.
Medium
TLS Configuration
Weak elliptic curve accepted for key exchange
The server negotiates an elliptic curve below 256 bits for at least one ECDHE cipher suite. Weak curves reduce the effective security margin of the key exchange well below modern standards.
High
Web
100%
HTTP Security Headers
Learn how it works
Info
3/7 pass
HTTP Security Headers
HSTS is not enforced
The site does not send a usable Strict-Transport-Security header, so browsers do not automatically upgrade future requests to HTTPS.
High
HTTP Security Headers
Content-Security-Policy is not enforced
The site does not send an enforced Content-Security-Policy header, leaving no restriction on script execution, framing, or resource loading beyond what other headers provide.
High
HTTP Security Headers
Referrer-Policy allows partial URL disclosure
The Referrer-Policy value allows the origin (and in some cases the full URL on same-origin navigation) to be disclosed to cross-origin destinations.
Low
HTTP Security Headers
Permissions-Policy is missing or ineffective
The site either does not send a Permissions-Policy header, or the header only lists directives with a wildcard allowlist that does not restrict anything.
Medium
Feedback