SCANTIDE ONLINE
Scantide Online Guide

Public Server Security Checklist: What Can Be Checked Without Logging In

A useful first-pass external review can inspect DNS, reachability, TLS, redirects, headers, cookies, service clues and infrastructure context without authenticating to the server.

Technical guideUpdated 25 September 2026Scantide Online
Short answer: A useful first-pass external review can inspect DNS, reachability, TLS, redirects, headers, cookies, service clues and infrastructure context without authenticating to the server.

Confirm what is reachable

Start with the expected hostname, HTTP/HTTPS behavior and any public service clues. Unexpected reachability is often more important than a minor configuration warning.

Validate the trust layer

Check certificate identity and expiry, HTTPS behavior and browser-facing security headers.

Review identity and mail posture

DNS, SPF and DMARC help explain where services live and how the domain presents its mail security policy.

Identify ownership and provider context

IP, hosting provider, ASN and jurisdiction clues help establish who operates the visible infrastructure.

Use the result to decide what needs deeper work

Scantide Online is designed as readable external evidence. A finding can lead to remediation, ownership review or a deeper specialist assessment where justified.

Practical depth: examples, failure modes and what to verify

Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.

Current Scantide detail

Current Scantide source: Public Server Security Assessment

Use Scantide Online to review public hosts, HTTPS, headers, DNS and infrastructure evidence for a readable first-pass public server security assessment.

Current Scantide source: Domain Security Scanner for DNS, HTTPS and Web Exposure

Use Scantide Online to check DNS and mail security, HTTPS/TLS, security headers, cookies and public infrastructure context from one domain scan.

Current Scantide source: Domain Security Scanner for DNS, HTTPS and Web Exposure

Scantide Online reviews public DNS, mail-security records, HTTP/HTTPS behavior, TLS, security headers, cookies, infrastructure and CVE-related context to provide a readable external assessment of a domain.

Current Scantide source: External Attack Surface Assessment and Discovery

External attack surface work begins with visibility: which hosts answer, which services are exposed and which systems appear to belong to the organization.

Current Scantide source: DNS, SPF and DMARC Security Checker

Scantide Online checks public DNS and mail-security signals including SPF and DMARC as part of a broader external domain assessment.

Field experience from the archive

Historical source · JufCorp: Securing your servers, users and customers online

Also, you external DNS server needs to be secured! Have a word with your ISP or whoever is running the external DNS server and see what they've got in place.

Quite often , they've set it up in the way that the primary MX might point to the secured, external provider or the secured, primary mail server interface and the secondary points directly to the mail server, thus not taking the way through the washing and security mechanisms in place but instead be delivered directly to the mail server.

Remember to check your mail queues on a regular basis If you're starting to have loads of undelivered mail to and from various domains you could actually have a DNS server that's under attack , not being able to service your Exchange server with required information .

Historical source · JufCorp: Securing your server environment - Part III - Operating systems

Whatever you'll be using your server for. have a look at any information that it "bleeds". This could for instance be headers telling any attacker exactly what version of software you're running. If possible, try to hide such information. There's no need for it to be visible and help a hacker find a way in. Simple checks using telnet to the ports your services might reveal some interesting information . Sadly, it's not possible to remove all headers etc but you should give it a go and remove as many as possible While on the subject, use SSL-certificates for any service where possible. Also make sure to set it up correctly (disable weak ciphers, enable HSTS, set correct HTTP headers, set TLS correctly etc ) . Have a look at Letsencrypt for instance for SSL certificates. It's free, supported by basically everyone and it'll probably get the job done for you . All you have to remember is to check that your certificates are renewed every three months.

Historical source · JufCorp: Security Reality Check: Why a Perfect Score Doesn't Mean You're Safe

This automated scanner focuses on infrastructure vulnerabilities, exposed services, and configuration issues. However, many critical security threats require manual testing, code review, or specialized tools. Ensure your security strategy addresses the following areas:

Historical source · JufCorp: Securing Windows Server with a baseline security

12. Enforce complex password policies! You won’t be well-liked but that’s not what you get paid for. If people are having trouble remembering passwords the have all over the world, maybe you could have them read this blog post I wrote about rememebering complex passwords and on the topic of online passwords and identities, they migh also want to read this post about protecting your online identity also.

Practical review checklist

Frequently asked questions

Can this replace a penetration test?

No. It is an external visibility and configuration review, not exploitation-based testing.

Why start with unauthenticated checks?

Because they show what any external observer can see and often reveal simple problems quickly.

Check the evidence with Scantide Online

External domain security, privacy and infrastructure assessment. Scantide is designed to show observable evidence and readable context rather than turn every observation into a vulnerability claim.

Run Scantide OnlineMore guidesAll Scantide guides