Website Security Findings
Findings are what Nivaronix’s scanner actually reports back after checking a site: a specific, named issue — a missing header, an unenforced email-authentication policy, a certificate about to expire — each with a severity rating, the exact evidence behind it, and a fix. Every finding page below documents one of those exact results, so if a scan of your site surfaces it, you can read precisely what it means before you act on it.
These come from configuration and posture checks — security headers, SSL/TLS certificates, DNS/DNSSEC/CAA records, and SPF/DMARC email authentication — not from malware scanning, exploit testing, or a penetration test. A finding here describes a gap between your current configuration and a known-good baseline, with a straightforward way to close it.
All findings
- Missing HSTS Header
What a missing Strict-Transport-Security header means, why it matters, and how to add HSTS on Nginx, Apache and Cloudflare.
- Missing Content-Security-Policy
What a missing Content-Security-Policy header means, why it matters for XSS defense, and how to add CSP on Nginx, Apache and Cloudflare.
- Missing X-Frame-Options Header
What a missing X-Frame-Options header means, why it enables clickjacking, and how to add it on Nginx, Apache and Cloudflare.
- Missing X-Content-Type-Options Header
What a missing X-Content-Type-Options header means, why MIME-sniffing is a risk, and how to add nosniff on Nginx, Apache and Cloudflare.
- Deprecated X-XSS-Protection Header
Why the X-XSS-Protection header is deprecated, what Nivaronix flags when it's present, and how to remove it safely.
- Self-Signed Certificate
What a self-signed certificate finding means, why it matters, severity, and how to replace it with a trusted CA certificate.
- SSL Certificate Expiring
What an SSL certificate expiring finding means, why it matters, severity, and how to renew before browsers show a warning.
- DNSSEC Not Enabled
What it means when Nivaronix reports DNSSEC Not Enabled, why it matters, severity, and how to enable DNSSEC without breaking your domain's resolution.
- No CAA Record
What it means when Nivaronix reports no CAA record, why it matters, severity, and how to publish a CAA record restricting certificate issuance to your CA.
- SPF Record Enforces a Hard Fail (-all)
What it means when Nivaronix reports an SPF hard fail, why -all is the strongest SPF setting, and how to verify your own record.
- DMARC Policy Is Monitoring Only (p=none)
What it means when Nivaronix reports a p=none DMARC policy, why monitor-only isn't protection, severity, and how to move to enforcement safely.
Find out which of these apply to you
These findings only mean something once you know which ones your own site triggers. A free scan checks all of them against your domain and returns the exact results, with evidence.
Scan your site for free