Website security
Website security checker
Run Ironfang's external checks on a domain in one pass: DNS, email authentication, HTTPS and its certificate, security headers and cookies, the software the site discloses, and the names in certificate transparency logs. Use it as a website or a domain security checker; each area links to a focused tool with the detail.
What this checks
- DNS: address records, nameserver redundancy, CAA, DNSSEC and dangling CNAMEs.
- Email authentication, from DNS only: SPF, DMARC, DKIM at common selectors, and whether a domain that sends no mail says so.
- TLS on port 443: HTTPS availability, certificate trust, name and expiry, old protocol versions, TLS 1.3 support and weak cipher suites.
- HTTP: the redirect to HTTPS, HSTS,
Content-Security-Policy,X-Content-Type-Options, clickjacking protection,Referrer-Policy,Permissions-Policy, version disclosure, cookie attributes andsecurity.txt. - Technology: software the home page discloses, and advertised versions that are end of life.
- Certificate transparency: names under the domain in public certificate logs, listed and not contacted.
What the result means
Results are grouped by area. For a registrable domain such as example.org the web checks cover both example.org and www.example.org; for a subdomain, only that name.
Each check passes, raises a finding, is informational, or could not be completed. A finding carries a severity for its potential impact and a separate confidence for how strong the evidence is, and names the one thing to change. There is no overall grade or score.
A clean result means these automated, low-impact checks found nothing to report. It does not mean the site is secure: they read public configuration and do not test the application, its logins or services on other ports.
How to fix common issues
No DMARC policy
Publish a TXT record at _dmarc.example.com such as v=DMARC1; p=none; rua=mailto:dmarc@example.com, review the reports, then move to p=quarantine and p=reject.
DMARC is in monitoring mode
Once reports show your legitimate mail passing, move to p=quarantine and then p=reject.
HSTS is not enabled
Add Strict-Transport-Security: max-age=31536000; includeSubDomains to HTTPS responses once every subdomain serves HTTPS. Start with a short max-age if you are unsure, then raise it.
No Content Security Policy
Start with a report-only policy (Content-Security-Policy-Report-Only) to see what your pages load, then enforce a policy such as default-src 'self' plus the sources you need.
TLS 1.0 is enabled
Configure the server to require TLS 1.2 or later. For nginx use ssl_protocols TLSv1.2 TLSv1.3;; for Apache SSLProtocol -all +TLSv1.2 +TLSv1.3. CDNs usually have a minimum TLS version setting.
No CAA records
Add a CAA record naming the certificate authorities you use, for example example.com. CAA 0 issue "letsencrypt.org". Check which authorities issue your current certificates first, so renewals keep working.
Software version disclosed in headers
Turn off version banners: server_tokens off; in nginx, ServerTokens Prod and ServerSignature Off in Apache, expose_php = Off in php.ini, and remove X-Powered-By where your framework adds it.
Cyber Essentials and ISO 27001
Cyber Essentials does not name DMARC, HSTS or CAA, but its secure configuration and security update management themes apply to internet-facing services in scope, and these results are technical evidence about how one domain looks from outside. In ISO/IEC 27001:2022 they bear on Annex A controls such as 8.9 Configuration management, 8.24 Use of cryptography and 5.14 Information transfer.
Evidence of a setting is not evidence of the process behind it. The organisation still has to establish who owns each domain and service, how changes are approved, how findings are prioritised and fixed, and how often the configuration is reviewed.
Scope and limitations
- It does not check exposed services. Connecting to ports beyond the web ports runs only in the External Security Check, for a domain you have verified.
- It checks the domain and its
www.name. Other subdomains are listed from certificate transparency logs but not checked; enter one on its own to check it. - Web checks read the home page and
/.well-known/security.txt. Other pages, anything behind a login and the application itself are not tested. - It is an automated external check that never attempts to exploit anything. It is not a penetration test, an audit or a certification.
Related guides
Questions
- Is my site secure if every check passes?
- Not necessarily. These are automated, low-impact checks of public configuration. They do not test the application, its logins or its code, and they are not a penetration test.
- Does it check my whole domain?
- It checks the domain's DNS and email records, and the website on the domain and its www name. Other subdomains are listed from certificate transparency logs but not checked; enter one on its own to check it.
- Why is there no score?
- Ironfang reports findings rather than a grade. Each has a severity, for its potential impact, and a confidence, for how strong the evidence is. Fix the high-severity, high-confidence ones first.
- Does checking a site affect it?
- It should not. A run makes DNS lookups through public resolvers, a few TLS handshakes and at most 8 HTTP requests per host, paced and with short timeouts, from Ironfang Security's published scanner address.
Related security tools
- Email security checker - Check MX, SPF, DMARC and DKIM together, and the protection of a domain that sends no mail.
- SSL/TLS checker - Check a site's HTTPS, certificate, expiry, TLS versions and weak cipher suites.
- HTTP security headers checker - Check a site's HSTS, CSP, framing, content-type, referrer and permissions headers.
- DNS security checker - Check a domain's address records, nameserver redundancy, CAA, DNSSEC and dangling CNAMEs.

