10 checks · 22% of the score
Security checks
Whether the page is served safely: HTTPS, the headers that limit what an attacker can do, and the email records that stop spoofing. 9 of these have a page of their own; every one is listed here with the severity it carries and when it is skipped.
Every check in this category
10- critical
- critical
Reports: SSL certificate is expired, expiring, or does not match the hostname.
security-ssl-validity
- high
- medium
Strict-Transport-Security (HSTS) header
Reports: Missing Strict-Transport-Security header.
security-hsts
- medium
Reports: Missing clickjacking protection.
Either X-Frame-Options or a CSP frame-ancestors directive satisfies this.
security-clickjacking
- medium
Reports: No SPF record, or more than one.
Without SPF anyone can send email claiming to be your domain. Two records is a permanent error at the receiving server, which is worse than none.
Skipped, and not counted either way, when the DNS lookup fails.
security-spf
- medium
Reports: No DMARC record, or a policy of p=none.
p=none monitors and enforces nothing.
Skipped, and not counted either way, when the DNS lookup fails.
security-dmarc
- low
- low
Reports: Missing X-Content-Type-Options header.
security-x-content-type-options
- low
No DKIM key at the common selectors
Reported as inconclusive rather than failed: selectors are chosen per mail provider and cannot be listed from DNS.
Skipped, and not counted either way, when the DNS lookup fails.
security-dkim