SCANTIDE ONLINE
Scantide Online Guide

Why One External Security Scan Is Not Enough

Certificates expire, DNS changes, providers move, subdomains appear and headers drift. Repeating external checks turns a one-time snapshot into change awareness.

Technical guideUpdated 25 September 2026Scantide Online
Short answer: Certificates expire, DNS changes, providers move, subdomains appear and headers drift. Repeating external checks turns a one-time snapshot into change awareness.

Public posture changes without a redesign project

A CDN migration, marketing platform, certificate renewal or DNS edit can change what users receive even when the application itself did not change.

Small configuration drift can have large effects

A missing redirect, expired certificate or accidentally removed security header can appear between formal security reviews.

History makes findings easier to interpret

Knowing that a new host appeared yesterday is more useful than simply seeing the host in today's report.

Use monitoring where continuity matters

Scantide's dashboard/monitoring capabilities complement one-off Online assessments when teams need recurring certificate and domain visibility.

Practical depth: examples, failure modes and what to verify

Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.

Current Scantide detail

Current Scantide source: Domain Security Scanner for DNS, HTTPS and Web Exposure

Use Scantide Online to check DNS and mail security, HTTPS/TLS, security headers, cookies and public infrastructure context from one domain scan.

Current Scantide source: Scantide Online – Domain Security, Privacy and Infrastructure Scanner

Scantide Online reviews public DNS, mail-security records, HTTP/HTTPS behavior, TLS, security headers, cookies, infrastructure and CVE-related context to provide a readable external assessment of a domain.

Current Scantide source: Public Server Security Assessment

Use Scantide Online to review public hosts, HTTPS, headers, DNS and infrastructure evidence for a readable first-pass public server security assessment.

Current Scantide source: DNS, SPF and DMARC Security Checker

Scantide Online checks public DNS and mail-security signals including SPF and DMARC as part of a broader external domain assessment.

Current Scantide source: Domain Security Scanner for DNS, HTTPS and Web Exposure

A domain security review should connect evidence across layers instead of treating DNS, TLS and web configuration as unrelated checks.

Field experience from the archive

Historical source · JufCorp: Securing your servers, users and customers online

Also, you external DNS server needs to be secured! Have a word with your ISP or whoever is running the external DNS server and see what they've got in place.

Historical source · JufCorp: Securing your server environment - Part III - Operating systems

Whatever you'll be using your server for. have a look at any information that it "bleeds". This could for instance be headers telling any attacker exactly what version of software you're running. If possible, try to hide such information. There's no need for it to be visible and help a hacker find a way in. Simple checks using telnet to the ports your services might reveal some interesting information . Sadly, it's not possible to remove all headers etc but you should give it a go and remove as many as possible While on the subject, use SSL-certificates for any service where possible. Also make sure to set it up correctly (disable weak ciphers, enable HSTS, set correct HTTP headers, set TLS correctly etc ) . Have a look at Letsencrypt for instance for SSL certificates. It's free, supported by basically everyone and it'll probably get the job done for you . All you have to remember is to check that your certificates are renewed every three months.

Historical source · JufCorp: Security Reality Check: Why a Perfect Score Doesn't Mean You're Safe

A perfect security score (100) does not mean your systems are fully protected. This automated scan detects common vulnerabilities but cannot identify all security risks. Results may contain false positives or miss certain vulnerabilities. Always verify findings manually and implement additional security measures.

Forgotten Servers: Regularly scan your network for unknown or forgotten servers. These become prime targets - unpatched, unmonitored, and exploitable.

Historical source · JufCorp: Juha Jurvanen

Currently I'm actually employed as IT Business Analyst. I still do cnsulting for external clients etc but not on a full time basis.

Practical review checklist

Frequently asked questions

How often should external checks run?

It depends on change rate and risk; important public services benefit from recurring monitoring.

Why not rely only on internal change control?

Because the delivered public result can differ from intended configuration and emergency changes can bypass normal processes.

Check the evidence with Scantide Online

External domain security, privacy and infrastructure assessment. Scantide is designed to show observable evidence and readable context rather than turn every observation into a vulnerability claim.

Run Scantide OnlineMore guidesAll Scantide guides