Ironfang Security
Security check reference
What each check looks at, the findings it can raise and how to fix them. Every finding in the portal links here.
35 checks and 51 possible findings, in the order a scan runs them.
DNS configuration
- Address recordsWhether the domain publishes A or AAAA records, so that it serves a website at its own name. A domain with none is noted, and the web, TLS and exposure checks are skipped for it.
- Nameserver redundancyHow many nameservers the domain is delegated to. With only one, the whole domain stops resolving whenever that server is unreachable.
- CAA recordsWhether the domain publishes CAA records, which name the certificate authorities allowed to issue certificates for it.
- DNSSECWhether the parent zone publishes a DS record for the domain, which is what makes its DNS answers signed and checkable by resolvers.
- Dangling DNS recordsWhether a CNAME record points at a target name that no longer resolves: the usual trace of a hosted service that was removed while its DNS record stayed.
TLS and HTTPS
- HTTPS availabilityWhether the site answers over HTTPS as well as plain HTTP, by opening a TLS connection to port 443.
- Certificate validityWhether the certificate the server presents is in date, chains to a publicly trusted certificate authority and covers the hostname that was requested.
- Certificate expiryHow long the certificate the server presents has left before it expires, and whether that is within 30 days.
- TLS protocol versionsWhich protocol versions the server accepts: whether obsolete SSL 3.0, TLS 1.0 and TLS 1.1 are still enabled, and whether TLS 1.3 is offered.
- Cipher suitesWhether the server accepts a connection using a cipher suite that is considered broken or weak, such as RC4, 3DES, NULL, export-grade or anonymous ciphers.
HTTP security configuration
- HTTP to HTTPS redirectWhether a plain HTTP request to the site is answered with a redirect to the same address over HTTPS.
- HTTP Strict Transport Security (HSTS)Whether HTTPS responses carry a Strict-Transport-Security header, and whether its max-age is long enough to protect occasional visitors.
- Content Security PolicyWhether the page sets a Content-Security-Policy header, and whether its script-src still allows inline scripts with 'unsafe-inline'.
- X-Content-Type-OptionsWhether responses carry X-Content-Type-Options: nosniff, which stops browsers guessing a file type and running it as something else.
- Clickjacking protectionWhether responses stop other sites framing the page, with a CSP frame-ancestors directive or the older X-Frame-Options header.
- Referrer-PolicyWhether responses set a Referrer-Policy header that limits how much of the page address is shared with other sites.
- Permissions-PolicyWhether responses set a Permissions-Policy header that switches off powerful browser features the site does not use.
- Server information disclosureWhether response headers such as Server and X-Powered-By reveal the exact version of the software behind the site.
- Cookie securityThe attributes on cookies the site sets over HTTPS: Secure on every cookie, HttpOnly on cookies that look like sessions, and SameSite.
- security.txtWhether the site publishes /.well-known/security.txt, and whether it has the Contact and Expires lines RFC 9116 requires, with an expiry still in the future.
Email-domain security
- SPFThe domain's SPF record: whether there is exactly one, whether it parses, whether it ends in a policy that rejects other senders, and whether evaluating it stays within 10 DNS lookups.
- DMARCThe DMARC record at _dmarc under the domain: whether it exists and parses, how strict its policy is, whether it applies to all mail and whether it asks for reports.
- DKIMWhether DKIM keys are published at the selectors common mail services use. Selectors cannot be listed from outside, so a key under another name is not ruled out.
- Non-sending domain protectionFor a domain with no MX records, whether it declares that it sends no mail with a strict SPF record and a DMARC reject policy.
Public service exposure
- Database portsWhether the common ports of databases and data stores (SQL Server, Oracle, MySQL, PostgreSQL, CouchDB, Redis, Cassandra, Elasticsearch, Memcached and MongoDB) accept a connection from the internet.
- Remote desktop portsWhether the Remote Desktop (RDP, 3389) or VNC (5900) port accepts a connection from the internet.
- SSHWhether port 22 accepts a connection and answers as an SSH service.
- Plaintext servicesWhether the Telnet (23) or FTP (21) port accepts a connection from the internet.
- File sharing (SMB)Whether the SMB port (445) used by Windows file sharing accepts a connection from the internet.
- Container APIsWhether the unencrypted Docker API port (2375) accepts a connection from the internet.
- Additional web servicesWhether a web-style port other than 80 and 443, such as 8080 or 8443, accepts a connection.
Externally visible technologies
- Technology inventoryWhich web server, CDN or framework the site's responses reveal. These are recorded as observations, not findings, and versions are noted only where the response states them.
- End-of-life softwareWhether a version string the server advertises belongs to software that no longer receives security updates. The version is inferred, so a match is shown as potential.
Certificate and subdomain discovery
Every finding has a severity, its potential impact, and a confidence, how strongly the evidence supports it. Findings inferred rather than observed are marked "Potential".
Severity and confidence
