Cluster

Security Spot-Checks

Security headers, TLS, and email authentication are all readable from a domain without login or credentials. This cluster covers how to grade each one and what the results tell you, drawn from the same security layer Bassethound returns in every dossier.

5 questions about security spot-checks

Related clusters

Frequently asked questions

Can you check a domain's security without scanning it?

Yes. Response headers, the TLS certificate, and the DNS TXT records for SPF, DKIM, and DMARC are all served publicly on request. Reading them is passive, not a scan, and touches nothing an ordinary browser or resolver would not.

Does a good header grade mean a site is secure?

No. The grade measures whether the defensive response headers (HSTS, CSP, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy) are set correctly. It says nothing about application logic, auth flows, or unpatched services, so read it as one spot-check, not a verdict.

Sniff a domain.

Run sniff_domain on any site and read its five-layer dossier in one call.

Sniff a domain