Skip to content

Website Security Guides

Guides are reference material: each one explains a single security control — a response header, a DNS record type, a certificate concept, or how Nivaronix’s score is calculated — in plain English. They cover what the control does, why it matters, and how to configure it on common servers (Nginx, Apache, Cloudflare), independent of any scan result.

If you already have a finding from a scan and want the fix, the matching guide is linked directly from that finding page. If you’re starting from scratch — deciding what to configure before you’ve scanned anything — browse by topic below: HTTP security headers, SSL/TLS and certificates, DNS/DNSSEC/CAA, and email authentication (SPF/DMARC).

All guides

  • Security Headers Guide

    A plain-English guide to the six HTTP security headers Nivaronix checks — what each one does, why it matters, and how to add it on Nginx, Apache and Cloudflare.

  • HSTS (Strict-Transport-Security)

    What HSTS does, why it prevents SSL-stripping attacks, and how to enable it on Nginx, Apache and Cloudflare.

  • Content-Security-Policy

    What Content-Security-Policy does, why it's a key defense against XSS, and how to configure it on Nginx, Apache and Cloudflare.

  • X-Frame-Options

    What X-Frame-Options does, why it stops clickjacking attacks, and how to set it on Nginx, Apache and Cloudflare.

  • X-Content-Type-Options

    What X-Content-Type-Options does, why MIME-sniffing protection matters, and how to enable it on Nginx, Apache and Cloudflare.

  • Referrer-Policy

    What Referrer-Policy does, why it prevents URL and token leakage, and how to configure it on Nginx, Apache and Cloudflare.

  • Permissions-Policy

    What Permissions-Policy does, why disabling unused browser APIs reduces attack surface, and how to configure it on Nginx, Apache and Cloudflare.

  • SSL/TLS Certificates

    A plain-language guide to SSL/TLS certificates: what they do, how the trust chain works, and the most common certificate problems that break sites.

  • TLS Versions Explained

    What TLS 1.0, 1.1, 1.2, and 1.3 actually differ on, why the older versions are considered weak, and what running modern TLS means in practice.

  • What Is DNSSEC?

    DNSSEC explained: how DS records and signing work, what a validating resolver actually checks, and why Nivaronix's check is presence/signature status, not full chain validation.

  • What Is a CAA Record?

    CAA records explained: syntax, the issue/issuewild/iodef tags, how certificate authorities check them, and how to publish one for your domain.

  • What Is SPF?

    SPF (Sender Policy Framework) explained: how the record works, the -all/~all/+all qualifiers, the 10-lookup limit, common mistakes, and how to check yours.

  • What Is DMARC?

    DMARC explained: how it builds on SPF, the p=none/quarantine/reject policy stages, aggregate reports, and how to roll it out without breaking mail.

  • What Is DKIM?

    DKIM explained: how selector-based signing keys work, how Nivaronix checks common selectors, why that's not a full DKIM directory lookup, and how to publish one.

  • robots.txt, sitemap.xml, Canonical & Noindex

    What robots.txt, sitemap.xml, canonical tags and noindex signals do, why Nivaronix checks them as SEO signals rather than security findings, and how to fix each one.

  • How Is Website Security Score Calculated?

    A quick guide: how website security score is calculated, what counts as a good score, and why fixing one issue doesn't always move the number.

  • HTTP to HTTPS Redirects Explained

    Why an HTTP-to-HTTPS redirect matters even when an HTTPS version already exists, what a correct 301 redirect chain looks like, common mistakes, and how it complements HSTS.

  • Cookie Security Attributes: Secure, HttpOnly, and SameSite Explained

    What the Secure, HttpOnly, and SameSite cookie attributes each do, an example Set-Cookie header with all three set, and why session and auth cookies need all three.

  • DNS Resolution & Reverse DNS Explained

    A plain-English guide to how DNS resolution and reverse DNS (PTR records) work, what an invalid IP range misconfiguration looks like, and why mail systems check both.

  • What Is Continuous Website Security Monitoring?

    Continuous website security monitoring explained: how it differs from a one-off scan, what triggers an alert, and the tradeoffs of scan frequency.

  • Agentless vs. Authenticated Website Security Assessment

    The difference between agentless (external, unauthenticated) and authenticated website security assessment, what each can and can't see, and which one Nivaronix is.

  • How to Verify a Security Fix Actually Worked

    Marking a ticket resolved isn't verification. How to confirm a security fix actually took effect: what to re-check, common false-fix traps, and why a rescan beats self-report.

  • How Agencies Can Monitor Security Across Client Websites

    A practical model for agencies monitoring security across many client sites: grouping by client, setting an escalation path, reporting under your own brand, and handling offboarding.

See where you stand first

Reading is optional — a free scan tells you exactly which of these controls your site is already missing, so you can start with the guides that apply to you.

Scan your site for free