Register Login

Domain Security Compliance Scanner

https://

Scan Results for internetsecure.org

November 22, 2024, 10:57 pm

Understanding Our Security Checks

SSL:

Valid SSL

Expiration: 2024-12-24 (31 days remaining)

Issuer: Google Trust Services

Authority: WE1

Download Certificate

TLS Configuration:

Strength: Strong

Version: TLSv1.3

Cipher: TLS_AES_256_GCM_SHA384

TLS (Transport Layer Security) encrypts data in transit, protecting against eavesdropping and tampering. Strong TLS configurations use up-to-date protocols and ciphers to ensure the highest level of security.

Content Security Policy (CSP):

Enabled

Great! Your site implements Content Security Policy. Ensure it's properly configured to maximize protection against XSS and other injection attacks.

X-Frame-Options:

Protected against clickjacking

X-Frame-Options header is present, helping to prevent clickjacking attacks by controlling how your site can be embedded in frames.

HTTP Strict Transport Security (HSTS):

Enabled

HSTS forces browsers to use HTTPS, preventing downgrade attacks and cookie hijacking.

Cookie Security:

All cookies are secure

Mixed Content:

No mixed content detected

Mixed content (HTTP resources on HTTPS pages) poses security risks, enabling potential attacks and content injection. Modern browsers may block it, breaking site functionality.

Web Application Firewall (WAF):

WAF detected: Cloudflare

A WAF provides an additional layer of security for your website. Ensure it's properly configured and regularly updated for optimal protection.

HTTP Security Headers:

Security Headers Score: 100/100
X-XSS-Protection

Helps prevent XSS attacks in older browsers.

X-Content-Type-Options

Prevents MIME type sniffing.

Referrer-Policy

Controls the Referer header for outgoing requests.

Permissions-Policy

Controls which browser features and APIs can be used.

Server Version:

cloudflare

In theory you want to hide your software or version but not all announcements are bad.

DNSSEC:

DNSSEC not enabled

DNSSEC adds a layer of trust to your domain name. It helps prevent DNS spoofing and cache poisoning attacks. Consider enabling it for enhanced security.

Nameservers:

  • jean.ns.cloudflare.com (173.245.58.121)
  • ed.ns.cloudflare.com (172.64.33.111)

DMARC:

DMARC record found

DMARC helps prevent email spoofing and protects your domain from unauthorized use in phishing attacks.

DKIM:

DKIM record found (selector: x)

DKIM adds a digital signature to emails, verifying that they were sent by an authorized sender and weren't altered in transit.


Help