Scantide Online Guide
Public Server Security Checklist: What Can Be Checked Without Logging In
A useful first-pass external review can inspect DNS, reachability, TLS, redirects, headers, cookies, service clues and infrastructure context without authenticating to the server.
Technical guideUpdated 25 September 2026Scantide Online
Confirm what is reachable
Start with the expected hostname, HTTP/HTTPS behavior and any public service clues. Unexpected reachability is often more important than a minor configuration warning.
Validate the trust layer
Check certificate identity and expiry, HTTPS behavior and browser-facing security headers.
Review identity and mail posture
DNS, SPF and DMARC help explain where services live and how the domain presents its mail security policy.
Identify ownership and provider context
IP, hosting provider, ASN and jurisdiction clues help establish who operates the visible infrastructure.
Use the result to decide what needs deeper work
Scantide Online is designed as readable external evidence. A finding can lead to remediation, ownership review or a deeper specialist assessment where justified.
Practical depth: examples, failure modes and what to verify
Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.
Current Scantide detail
Current Scantide source: Public Server Security AssessmentUse Scantide Online to review public hosts, HTTPS, headers, DNS and infrastructure evidence for a readable first-pass public server security assessment.
Current Scantide source: Domain Security Scanner for DNS, HTTPS and Web ExposureUse Scantide Online to check DNS and mail security, HTTPS/TLS, security headers, cookies and public infrastructure context from one domain scan.
Current Scantide source: Domain Security Scanner for DNS, HTTPS and Web ExposureScantide Online reviews public DNS, mail-security records, HTTP/HTTPS behavior, TLS, security headers, cookies, infrastructure and CVE-related context to provide a readable external assessment of a domain.
Current Scantide source: External Attack Surface Assessment and DiscoveryExternal attack surface work begins with visibility: which hosts answer, which services are exposed and which systems appear to belong to the organization.
Current Scantide source: DNS, SPF and DMARC Security CheckerScantide Online checks public DNS and mail-security signals including SPF and DMARC as part of a broader external domain assessment.
Field experience from the archive
Historical source · JufCorp: Securing your servers, users and customers onlineAlso, you external DNS server needs to be secured! Have a word with your ISP or whoever is running the external DNS server and see what they've got in place.
Quite often , they've set it up in the way that the primary MX might point to the secured, external provider or the secured, primary mail server interface and the secondary points directly to the mail server, thus not taking the way through the washing and security mechanisms in place but instead be delivered directly to the mail server.
Remember to check your mail queues on a regular basis If you're starting to have loads of undelivered mail to and from various domains you could actually have a DNS server that's under attack , not being able to service your Exchange server with required information .
Historical source · JufCorp: Securing your server environment - Part III - Operating systemsWhatever you'll be using your server for. have a look at any information that it "bleeds". This could for instance be headers telling any attacker exactly what version of software you're running. If possible, try to hide such information. There's no need for it to be visible and help a hacker find a way in. Simple checks using telnet to the ports your services might reveal some interesting information . Sadly, it's not possible to remove all headers etc but you should give it a go and remove as many as possible While on the subject, use SSL-certificates for any service where possible. Also make sure to set it up correctly (disable weak ciphers, enable HSTS, set correct HTTP headers, set TLS correctly etc ) . Have a look at Letsencrypt for instance for SSL certificates. It's free, supported by basically everyone and it'll probably get the job done for you . All you have to remember is to check that your certificates are renewed every three months.
Historical source · JufCorp: Security Reality Check: Why a Perfect Score Doesn't Mean You're SafeThis automated scanner focuses on infrastructure vulnerabilities, exposed services, and configuration issues. However, many critical security threats require manual testing, code review, or specialized tools. Ensure your security strategy addresses the following areas:
Historical source · JufCorp: Securing Windows Server with a baseline security12. Enforce complex password policies! You won’t be well-liked but that’s not what you get paid for. If people are having trouble remembering passwords the have all over the world, maybe you could have them read this blog post I wrote about rememebering complex passwords and on the topic of online passwords and identities, they migh also want to read this post about protecting your online identity also.
Practical review checklist
- Use Scantide Online to review public hosts, HTTPS, headers, DNS and infrastructure evidence for a readable first-pass public server security assessment.
- Use Scantide Online to check DNS and mail security, HTTPS/TLS, security headers, cookies and public infrastructure context from one domain scan.
- Scantide Online reviews public DNS, mail-security records, HTTP/HTTPS behavior, TLS, security headers, cookies, infrastructure and CVE-related context to provide a readable external assessment of a domain.
- External attack surface work begins with visibility: which hosts answer, which services are exposed and which systems appear to belong to the organization.
- Scantide Online checks public DNS and mail-security signals including SPF and DMARC as part of a broader external domain assessment.
- Also, you external DNS server needs to be secured!
- This automated scanner focuses on infrastructure vulnerabilities, exposed services, and configuration issues.