Skip to content

SCAN FAMILY

Site security

NO COUNT PUBLISHED / COLLECTED, NOT YET GRADED

What a domain tells the public about itself before anyone signs in: its mail authentication records, the certificate it presents, and the instructions its responses carry. Collected on every scan, reported as evidence, and deliberately ungraded.

Free, no signup. Your report is a shareable link.

Sample reading. This family reads not-measured - the slate dash, not a short arc. It is not a failing grade.

What it measures

  • Whether the domain publishes the DNS records that let a receiver tell real mail from forged mail.
  • Whether the certificate a browser is handed is valid, current, complete and actually for this name.
  • Whether plain HTTP reaches HTTPS, and what the response headers instruct a browser to do.
  • Whether cookies carry the attributes that keep them from being read or sent where they should not be.

What it cannot

  • Grade any of it. This family is collected and reported as evidence, and carries no score, because no threshold has been measured against real domains yet.
  • See anything that is not public. There is no authentication, no session, and no view of anything behind a login.
  • Confirm an announced MTA-STS policy is served or valid - the policy file is deliberately never fetched.
  • Prove a negative. A DKIM key missing from the common selectors means the lookup found nothing there, not that the domain does not sign.
  • Tell you a site is secure. A reading describes one moment, from outside, and is evidence rather than certification.

Scanning is passive

We read public DNS and public responses. Nothing is probed. No port range is swept, no path is guessed, no payload is sent, and no attempt is made to authenticate as anyone.

Where the scan does connect, it connects only to the two ports a browser connects to, and reads what the server volunteers in its own handshake and its own redirect. Below is everything a scan sends, as counts rather than as adjectives, because a claim about network behaviour should be checkable.

A report is evidence of what could be seen from outside at one moment. It is never certification, and it never asserts that a site is secure or compliant.

  • To public DNS resolvers

    TXT and CAA lookups about the domain - SPF, DMARC, MTA-STS, TLS-RPT, and one per common DKIM selector. These ask a resolver about the domain; they send nothing to it.

  • To a public DoH resolver

    One HTTPS request for the DNSKEY record, to establish DNSSEC. It goes to a third-party recursive resolver, never to the scanned domain.

  • To the domain, on port 443

    TLS handshakes that read the certificate the server itself presents, then close. No application data is sent over them.

  • To the domain, on port 80

    One GET of the site root, to see whether it redirects. The root only - never a guessed path.

  • For headers and cookies

    Nothing. Both are read from responses the scan had already received.

What it reads

Grouped as the engine groups them. How many findings each area produces depends on what was actually observed, so no total is published here - there is no constant in the engine that counts them, and a number arrived at any other way would not be one the scan computed.

From public DNS

  • SPFemail.spf

    Whether a sender policy is published, whether there is exactly one, what it asserts about unlisted senders, and whether it stays inside the ten-lookup limit.

  • DMARCemail.dmarc

    Whether a policy exists, whether it enforces or only monitors, what percentage of mail it applies to, and whether reports are collected anywhere.

  • DKIMemail.dkim

    Whether a signing key is published at any of the common selectors. A miss is what the probe did not find, never proof that the domain does not sign.

  • CAAtls.caa

    Whether certificate issuance is restricted to named authorities.

  • MTA-STSemail.mta_sts

    Whether a policy is announced in DNS. The policy file itself is deliberately not fetched, so an announcement is not evidence of a served or valid policy.

  • TLS-RPTemail.tls_rpt

    Whether a reporting address is published for TLS delivery failures.

  • DNSSECdns.dnssec

    Whether the zone is signed and whether the signature validates.

From the connection and the response

  • Certificate and TLStransport

    Expiry, validity dates, self-signing, chain completeness, name coverage, and the TLS version actually negotiated.

  • HTTP to HTTPStransport.http

    Whether plain HTTP on port 80 redirects, and with what status.

  • Security headersheaders

    Content-Security-Policy, HSTS, framing protection, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and whether responses disclose software versions.

  • Cookiescookies

    Secure, HttpOnly and SameSite attributes, and whether any cookie is scoped to a parent domain. Cookie values are never recorded.

How a finding reads

Four words, and none of them is a grade. There is no failing verdict in this family at all - a block with no measured threshold has no business failing anyone, and the engine has a test asserting one cannot exist.

  • ok

    Configured, and configured the way the RFC recommends.

  • warn

    A gap, or something present but weak.

  • risk

    Actively harmful: it makes spoofing easier, or breaks evaluation for every receiver.

  • indeterminate

    We could not establish the answer. Never recorded as absent.

The other sightings

Taken independently. None of them waits on another.