Skip to content

Checklist

Website security checklist

What a small organisation should have in place for its public website and domain, as a list to work through. Tick items as you confirm them; where a free tool checks part of an item, it is linked.

Reviewed October 2026.

How to use this checklist

The checklist covers the public website, the domain it runs on, the email domain that shares its name, and the accounts that control them. Work through it with whoever runs the site, whether a colleague, a web agency or the hosting provider. Tick an item when you have confirmed it, not when you assume it.

Where a free tool checks part of an item, it is linked beside it. A tool shows the public configuration at the moment it ran. A clean result does not show that the site is secure, and many items, such as backups, admin accounts and who responds to alerts, can only be confirmed from inside the organisation.

What the tools can show, and what only you can

Ironfang can check

  • HTTPS, the certificate, TLS versions and cipher suites
  • Security headers and cookie attributes
  • Nameservers, CAA, DNSSEC and dangling records
  • SPF, DMARC, and DKIM at a selector you name
  • Software versions the site advertises, and security.txt
  • For a verified domain, a fixed list of exposed services such as databases and remote desktop

The organisation must establish

  • Who owns the site, the domain and each supplier relationship
  • That updates are applied, and that backups exist and restore
  • Who has admin access, and that each of them uses MFA
  • Who receives alerts and security reports, and acts on them

The list does not cover the security of the site's own code, such as its login, forms or payment flow. That needs a code review or a penetration test.

The checklist

0 of 45 done

Your ticks are kept in this browser only.

HTTPS and certificates

  • Free tool: SSL/TLS checker
  • Free tool: Website security checker
  • Free tool: Certificate checker
  • Free tool: Certificate expiry checker
  • Free tool: HSTS checker

TLS versions and cipher suites

Security headers

Cookies

  • Free tool: Cookie security checker

DNS and the domain

  • Free tool: DNS security checker
  • Free tool: CAA checker
  • Free tool: DNSSEC checker
  • Free tool: Dangling DNS checker
  • Free tool: Subdomain finder

The email domain

  • Free tool: SPF checker
  • Free tool: DKIM checker
  • Free tool: DMARC checker
  • Free tool: Email security checker

Software updates and end-of-life software

  • Free tool: End-of-life software checker

Admin access and MFA

  • Free tool: Exposed services checker

Backups

Monitoring

  • Free tool: Website security checker

security.txt and reporting

  • Free tool: security.txt checker

What to do with the gaps

Not every unticked item is equally urgent. A sensible order:

  1. Anything open to the internet that should not be: databases, remote desktop, file sharing and admin interfaces.
  2. Missing HTTPS, and expired, untrusted or mismatched certificates.
  3. Admin accounts without MFA, and software past its end of life.
  4. Email spoofing: SPF and DMARC first, then move DMARC towards reject.
  5. Hardening: security headers, CAA, DNSSEC and security.txt.

Each finding from the tools links to its page in the check reference, which explains the finding and how to fix it. Run the tool again after a fix to confirm it.

Where you decide not to do something, such as DNSSEC on a domain whose provider does not support it, write down the decision and the reason. A recorded decision can be reviewed later; an unticked box only raises the question again.

The External Security Check runs every external check on a verified domain, including exposed services, and records each finding with its evidence, severity and fix. Results are kept with the domain's history, and continuous monitoring rechecks on a schedule and tells you when something changes. It is free during the preview.

For the detail behind each group, see TLS and certificates, HTTP security headers, DNS security and email authentication.

Sources

Checked on the review date above. Standards and schemes change; the source is the authority.