Reviewed October 2026.
How to use this checklist
The checklist covers the public website, the domain it runs on, the email domain that shares its name, and the accounts that control them. Work through it with whoever runs the site, whether a colleague, a web agency or the hosting provider. Tick an item when you have confirmed it, not when you assume it.
Where a free tool checks part of an item, it is linked beside it. A tool shows the public configuration at the moment it ran. A clean result does not show that the site is secure, and many items, such as backups, admin accounts and who responds to alerts, can only be confirmed from inside the organisation.
What the tools can show, and what only you can
Ironfang can check
- HTTPS, the certificate, TLS versions and cipher suites
- Security headers and cookie attributes
- Nameservers, CAA, DNSSEC and dangling records
- SPF, DMARC, and DKIM at a selector you name
- Software versions the site advertises, and security.txt
- For a verified domain, a fixed list of exposed services such as databases and remote desktop
The organisation must establish
- Who owns the site, the domain and each supplier relationship
- That updates are applied, and that backups exist and restore
- Who has admin access, and that each of them uses MFA
- Who receives alerts and security reports, and acts on them
The list does not cover the security of the site's own code, such as its login, forms or payment flow. That needs a code review or a penetration test.
The checklist
0 of 45 done
Your ticks are kept in this browser only.
HTTPS and certificates
TLS versions and cipher suites
Security headers
DNS and the domain
The email domain
Software updates and end-of-life software
Admin access and MFA
Backups
Monitoring
security.txt and reporting
What to do with the gaps
Not every unticked item is equally urgent. A sensible order:
- Anything open to the internet that should not be: databases, remote desktop, file sharing and admin interfaces.
- Missing HTTPS, and expired, untrusted or mismatched certificates.
- Admin accounts without MFA, and software past its end of life.
- Email spoofing: SPF and DMARC first, then move DMARC towards reject.
- Hardening: security headers, CAA, DNSSEC and security.txt.
Each finding from the tools links to its page in the check reference, which explains the finding and how to fix it. Run the tool again after a fix to confirm it.
Where you decide not to do something, such as DNSSEC on a domain whose provider does not support it, write down the decision and the reason. A recorded decision can be reviewed later; an unticked box only raises the question again.
The External Security Check runs every external check on a verified domain, including exposed services, and records each finding with its evidence, severity and fix. Results are kept with the domain's history, and continuous monitoring rechecks on a schedule and tells you when something changes. It is free during the preview.
For the detail behind each group, see TLS and certificates, HTTP security headers, DNS security and email authentication.
Sources
Checked on the review date above. Standards and schemes change; the source is the authority.
- NCSC: Small organisations guide to cyber security
- NCSC: Backing up your data
- NCSC: Keeping devices and software up to date
- NCSC: Obsolete products
- NCSC: Multi-factor authentication for your corporate online services
- NCSC: Managing public domain names
- NCSC: Using TLS to protect data
- NCSC: Email security and anti-spoofing
- NCSC: Vulnerability Disclosure Toolkit
- RFC 9116: A File Format to Aid in Security Vulnerability Disclosure
- RFC 8996: Deprecating TLS 1.0 and TLS 1.1
- RFC 6797: HTTP Strict Transport Security (HSTS)
- OWASP: HTTP Security Response Headers Cheat Sheet
- MDN: Set-Cookie

