Blog
Contact
Sign in
Scan complete
C
74/100
hornetsecurity.com
1 critical issue needs immediate attention.
16/16
checks
69
passed
finished
Scan timestamps
Created
Jul 25, 2026, 2:17 PM
Started
Jul 25, 2026, 2:17 PM
Finished
Jul 25, 2026, 2:17 PM
Updated
Jul 25, 2026, 2:17 PM
Export PDF
Re-scan
Findings by severity
79 results
1
Critical
3
High
1
Medium
5
Low
69
Pass
Report coverage
100%
Full coverage - every planned check was evaluated.
16 skipped
All
95
Critical
1
High
3
Medium
1
Low
5
Pass
69
Skipped
16
Email
100%
Domain Alignment (DMARC)
Learn how it works
Info
6/7 pass
Domain Alignment (DMARC)
DMARC alignment is relaxed
The DMARC record allows relaxed identifier alignment for DKIM or SPF.
Low
Certificate Binding (DANE)
Learn how it works
Info
1/5 pass
Certificate Binding (DANE)
No MX host TLSA zone is protected by DNSSEC
None of the MX hosts have DNSSEC on their TLSA lookup zones. DANE SMTP cannot function without DNSSEC, as sending servers will ignore TLSA records from unsigned zones.
Critical
Transport Policy (MTA-STS)
Learn how it works
Info
1/6 pass
Transport Policy (MTA-STS)
MTA-STS DNS record is missing
The domain does not publish an MTA-STS TXT record, so sending servers cannot discover or enforce an MTA-STS policy.
High
TLS Reporting (TLS-RPT)
Learn how it works
Info
1/4 pass
TLS Reporting (TLS-RPT)
No TLS-RPT record found
The domain does not publish a TLS-RPT record. Sending servers cannot report TLS errors to this domain.
High
DNS
100%
DNS Integrity (DNSSEC)
Learn how it works
Info
0/7 pass
DNS Integrity (DNSSEC)
DNSSEC is not enabled
The parent zone does not publish a DS record for this domain.
Medium
DNS Health (Delegation & Exposure)
Learn how it works
Info
7/8 pass
DNS Health (Delegation & Exposure)
SOA serial does not use the recommended format
The SOA record is otherwise valid, but the serial number does not follow the recommended YYYYMMDDnn date format.
Low
CAA and Certificate Issuance Surface
Learn how it works
Info
4/6 pass
CAA and Certificate Issuance Surface
Certificate issuance is not pinned
The CAA records authorize a CA but do not restrict issuance to a specific account or validation method.
Low
CAA and Certificate Issuance Surface
No S/MIME issuance policy is published
The domain does not publish an issuemail CAA property, so any CA may issue S/MIME certificates for its email addresses; note that issue and issuewild do not restrict S/MIME issuance.
Low
Web
100%
HTTP Security Headers
Learn how it works
Info
5/7 pass
HTTP Security Headers
Content-Security-Policy is weak and bypass-prone
The CSP allows inline script execution without a nonce or hash, a wildcard or http:/data: script source, or does not restrict script sources at all. Such policies are commonly reported as bypassable in independent CSP research.
High
HTTP Security Headers
Deprecated security headers are present
The response sends one or more deprecated headers (X-XSS-Protection, Expect-CT, or Public-Key-Pins) that modern browsers ignore or that carry their own operational risk (HPKP).
Low
Feedback