What problem does it solve?
It helps identify weaknesses in an organization’s web and email security posture by reviewing HTTP security headers, Content Security Policy behavior, HSTS configuration, DNS-based email authentication records, and common security-discovery endpoints.
Core Features & Use Cases
- HTTP security header assessment: Detects presence and strength of key headers like HSTS, CSP, X-Frame-Options, X-Content-Type-Options, and Referrer-Policy to highlight missing protections and risky configurations.
- Content Security Policy analysis: Evaluates CSP directives for unsafe allowances (such as unsafe-inline or unsafe-eval), derives third-party domains, and estimates overall CSP strength.
- Email security DNS record review: Checks SPF, DKIM, and DMARC values to assess spoofing resistance and enforcement/reporting posture.
- Security discovery file validation: Verifies availability and content signals of security.txt (and related paths) to ensure security contact and operational expectations are present.
Quick Start
Ask it to analyze your Phase 2 HTTP, DNS, HTML, and repository signals for missing or weak security headers, risky CSP directives, weak email authentication records, and absent security-discovery files.