Blog
Contact
Sign in
Scan complete
D
67/100
benchmark.pl
1 critical issue needs immediate attention.
16/16
checks
52
passed
finished
Scan timestamps
Created
Aug 9, 2026, 5:10 PM
Started
Aug 9, 2026, 5:10 PM
Finished
Aug 9, 2026, 5:10 PM
Updated
Aug 9, 2026, 5:10 PM
Export PDF
Re-scan
Findings by severity
69 results
1
Critical
7
High
4
Medium
5
Low
52
Pass
Report coverage
98.53%
26 skipped - these limit completeness.
26 skipped
All
95
Critical
1
High
7
Medium
4
Low
5
Pass
52
Skipped
26
Email
96%
Sender Authentication (SPF)
Learn how it works
Info
6/7 pass
Sender Authentication (SPF)
SPF policy does not use strict fail mode
The SPF policy does not fully reject unauthorized senders.
Medium
Domain Alignment (DMARC)
Learn how it works
Info
2/7 pass
Domain Alignment (DMARC)
DMARC policy is monitoring only
The DMARC policy uses p=none and does not ask receivers to block or quarantine failing mail.
High
Domain Alignment (DMARC)
DMARC subdomain policy is weak
Subdomains are not protected by an enforcement policy.
High
Domain Alignment (DMARC)
DMARC reporting destination is not usable
The DMARC aggregate reporting destination is invalid, unsupported, or not authorized.
High
Domain Alignment (DMARC)
DMARC alignment is relaxed
The DMARC record allows relaxed identifier alignment for DKIM or SPF.
Low
Transport Encryption (SMTP TLS)
Learn how it works
Info
4/5 pass
Transport Encryption (SMTP TLS)
Some MX hosts negotiate TLS 1.2 instead of TLS 1.3
All MX hosts meet the minimum TLS 1.2 requirement, but at least one does not support TLS 1.3.
Low
Certificate Binding (DANE)
Learn how it works
Info
1/5 pass
Certificate Binding (DANE)
No MX host TLSA zone is protected by DNSSEC
None of the MX hosts have DNSSEC on their TLSA lookup zones. DANE SMTP cannot function without DNSSEC, as sending servers will ignore TLSA records from unsigned zones.
Critical
Transport Policy (MTA-STS)
Learn how it works
Info
1/6 pass
Transport Policy (MTA-STS)
MTA-STS DNS record is missing
The domain does not publish an MTA-STS TXT record, so sending servers cannot discover or enforce an MTA-STS policy.
High
TLS Reporting (TLS-RPT)
Learn how it works
Info
1/4 pass
TLS Reporting (TLS-RPT)
No TLS-RPT record found
The domain does not publish a TLS-RPT record. Sending servers cannot report TLS errors to this domain.
High
DNS
100%
DNS Integrity (DNSSEC)
Learn how it works
Info
0/7 pass
DNS Integrity (DNSSEC)
DNSSEC is not enabled
The parent zone does not publish a DS record for this domain.
Medium
CAA and Certificate Issuance Surface
Learn how it works
Info
1/6 pass
CAA and Certificate Issuance Surface
No CAA record is published
The domain does not publish a CAA record, so any publicly trusted certificate authority may issue certificates for it after standard validation.
Low
TLS
100%
TLS Certificate
Learn how it works
Info
8/9 pass
TLS Certificate
Certificate expires soon
The server's TLS certificate is valid but expires within 30 days. If renewal is not automated, connections will start failing with certificate errors once it expires.
Medium
Web
100%
HTTP Security Headers
Learn how it works
Info
2/7 pass
HTTP Security Headers
HSTS is not enforced
The site does not send a usable Strict-Transport-Security header, so browsers do not automatically upgrade future requests to HTTPS.
High
HTTP Security Headers
Content-Security-Policy is weak and bypass-prone
The CSP allows inline script execution without a nonce or hash, a wildcard or http:/data: script source, or does not restrict script sources at all. Such policies are commonly reported as bypassable in independent CSP research.
High
HTTP Security Headers
Referrer-Policy allows partial URL disclosure
The Referrer-Policy value allows the origin (and in some cases the full URL on same-origin navigation) to be disclosed to cross-origin destinations.
Low
HTTP Security Headers
Permissions-Policy is missing or ineffective
The site either does not send a Permissions-Policy header, or the header only lists directives with a wildcard allowlist that does not restrict anything.
Medium
HTTP Security Headers
Deprecated security headers are present
The response sends one or more deprecated headers (X-XSS-Protection, Expect-CT, or Public-Key-Pins) that modern browsers ignore or that carry their own operational risk (HPKP).
Low
Feedback