Skip to content

Website security

Website security checker

Run Ironfang's external checks on a domain in one pass: DNS, email authentication, HTTPS and its certificate, security headers and cookies, the software the site discloses, and the names in certificate transparency logs. Use it as a website or a domain security checker; each area links to a focused tool with the detail.

Checked from Ironfang Security's scanner address with the same low-impact limits as a scan. Nothing you enter is kept.

What this checks

What the result means

Results are grouped by area. For a registrable domain such as example.org the web checks cover both example.org and www.example.org; for a subdomain, only that name.

Each check passes, raises a finding, is informational, or could not be completed. A finding carries a severity for its potential impact and a separate confidence for how strong the evidence is, and names the one thing to change. There is no overall grade or score.

A clean result means these automated, low-impact checks found nothing to report. It does not mean the site is secure: they read public configuration and do not test the application, its logins or services on other ports.

How to fix common issues

No DMARC policy

Publish a TXT record at _dmarc.example.com such as v=DMARC1; p=none; rua=mailto:dmarc@example.com, review the reports, then move to p=quarantine and p=reject.

More in the DMARC check reference

DMARC is in monitoring mode

Once reports show your legitimate mail passing, move to p=quarantine and then p=reject.

More in the DMARC check reference

HSTS is not enabled

Add Strict-Transport-Security: max-age=31536000; includeSubDomains to HTTPS responses once every subdomain serves HTTPS. Start with a short max-age if you are unsure, then raise it.

More in the HTTP Strict Transport Security check reference

No Content Security Policy

Start with a report-only policy (Content-Security-Policy-Report-Only) to see what your pages load, then enforce a policy such as default-src 'self' plus the sources you need.

More in the Content Security Policy check reference

TLS 1.0 is enabled

Configure the server to require TLS 1.2 or later. For nginx use ssl_protocols TLSv1.2 TLSv1.3;; for Apache SSLProtocol -all +TLSv1.2 +TLSv1.3. CDNs usually have a minimum TLS version setting.

More in the TLS protocol versions check reference

No CAA records

Add a CAA record naming the certificate authorities you use, for example example.com. CAA 0 issue "letsencrypt.org". Check which authorities issue your current certificates first, so renewals keep working.

More in the CAA records check reference

Software version disclosed in headers

Turn off version banners: server_tokens off; in nginx, ServerTokens Prod and ServerSignature Off in Apache, expose_php = Off in php.ini, and remove X-Powered-By where your framework adds it.

More in the Server information disclosure check reference

Cyber Essentials and ISO 27001

Cyber Essentials does not name DMARC, HSTS or CAA, but its secure configuration and security update management themes apply to internet-facing services in scope, and these results are technical evidence about how one domain looks from outside. In ISO/IEC 27001:2022 they bear on Annex A controls such as 8.9 Configuration management, 8.24 Use of cryptography and 5.14 Information transfer.

Evidence of a setting is not evidence of the process behind it. The organisation still has to establish who owns each domain and service, how changes are approved, how findings are prioritised and fixed, and how often the configuration is reviewed.

Scope and limitations

Related guides

Questions

Is my site secure if every check passes?
Not necessarily. These are automated, low-impact checks of public configuration. They do not test the application, its logins or its code, and they are not a penetration test.
Does it check my whole domain?
It checks the domain's DNS and email records, and the website on the domain and its www name. Other subdomains are listed from certificate transparency logs but not checked; enter one on its own to check it.
Why is there no score?
Ironfang reports findings rather than a grade. Each has a severity, for its potential impact, and a confidence, for how strong the evidence is. Fix the high-severity, high-confidence ones first.
Does checking a site affect it?
It should not. A run makes DNS lookups through public resolvers, a few TLS handshakes and at most 8 HTTP requests per host, paced and with short timeouts, from Ironfang Security's published scanner address.

Related security tools