Blog
Contact
Sign in
Scan complete
C
72/100
google.com
Changed · score unchanged
Compare
1 critical issue needs immediate attention.
10/10
checks
34
passed
finished
Scan timestamps
Created
Jul 7, 2026, 7:00 AM
Started
Jul 7, 2026, 7:01 AM
Finished
Jul 7, 2026, 7:01 AM
Updated
Jul 7, 2026, 7:01 AM
Export PDF
Re-scan
Findings by severity
39 results
1
Critical
0
High
2
Medium
2
Low
34
Pass
Report coverage
97%
14 skipped - these limit completeness.
14 skipped
All
53
Critical
1
Medium
2
Low
2
Pass
34
Skipped
14
Email
96%
Sender Authentication (SPF)
Learn how it works
Info
6/7 pass
Sender Authentication (SPF)
SPF policy does not use strict fail mode
The SPF policy does not fully reject unauthorized senders.
Medium
Domain Alignment (DMARC)
Learn how it works
Info
6/7 pass
Domain Alignment (DMARC)
DMARC alignment is relaxed
The DMARC record allows relaxed identifier alignment for DKIM or SPF.
Low
Certificate Binding (DANE)
Learn how it works
Info
1/5 pass
Certificate Binding (DANE)
No MX host TLSA zone is protected by DNSSEC
None of the MX hosts have DNSSEC on their TLSA lookup zones. DANE SMTP cannot function without DNSSEC, as sending servers will ignore TLSA records from unsigned zones.
Critical
DNS
100%
DNS Integrity (DNSSEC)
Learn how it works
Info
0/6 pass
DNS Integrity (DNSSEC)
DNSSEC is not enabled
The parent zone does not publish a DS record for this domain.
Medium
Web
100%
Disclosure Policy (security.txt)
Learn how it works
Info
3/4 pass
Disclosure Policy (security.txt)
Expires is set more than one year in the future
The Expires date is valid and in the future, but RFC 9116 recommends keeping the expiry within one year to avoid the file becoming stale.
Low
Feedback