A security header configured on the origin may disappear or change at a CDN, proxy or load balancer. External review verifies the actual public response.
Prioritize by function
HSTS, CSP, frame protections, X-Content-Type-Options, Referrer-Policy and Permissions-Policy address different browser behaviors.
Avoid binary thinking
A missing header is not equal to a critical vulnerability. The page purpose, browser behavior and other controls determine importance.
Online gives a public-domain view
Scantide Online reviews security headers together with TLS, DNS, cookies and infrastructure. Observe can complement that with live browser-visible page behavior.
Practical depth: examples, failure modes and what to verify
Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.
Current Scantide detail
Current Scantide source: Website Security Header ScannerScantide Online reviews website security headers such as HSTS, CSP, X-Frame-Options and related browser controls in the context of the public site.
Current Scantide source: Domain Security Scanner for DNS, HTTPS and Web ExposureUse Scantide Online to check DNS and mail security, HTTPS/TLS, security headers, cookies and public infrastructure context from one domain scan.
Current Scantide source: Public Server Security AssessmentUse Scantide Online to review public hosts, HTTPS, headers, DNS and infrastructure evidence for a readable first-pass public server security assessment.
Current Scantide source: DNS, SPF and DMARC Security CheckerScantide Online reviews public DNS, mail-security records, HTTP/HTTPS behavior, TLS, security headers, cookies, infrastructure and CVE-related context to provide a readable external assessment of a domain.
Current Scantide source: DNS, SPF and DMARC Security CheckerScantide Online checks public DNS and mail-security signals including SPF and DMARC as part of a broader external domain assessment.
Field experience from the archive
Historical source · JufCorp: Securing your server environment - Part III - Operating systemsWhatever you'll be using your server for. have a look at any information that it "bleeds". This could for instance be headers telling any attacker exactly what version of software you're running. If possible, try to hide such information. There's no need for it to be visible and help a hacker find a way in. Simple checks using telnet to the ports your services might reveal some interesting information . Sadly, it's not possible to remove all headers etc but you should give it a go and remove as many as possible While on the subject, use SSL-certificates for any service where possible. Also make sure to set it up correctly (disable weak ciphers, enable HSTS, set correct HTTP headers, set TLS correctly etc ) . Have a look at Letsencrypt for instance for SSL certificates. It's free, supported by basically everyone and it'll probably get the job done for you . All you have to remember is to check that your certificates are renewed every three months.
Historical source · JufCorp: Security Reality Check: Why a Perfect Score Doesn't Mean You're SafeThis automated scanner focuses on infrastructure vulnerabilities, exposed services, and configuration issues. However, many critical security threats require manual testing, code review, or specialized tools. Ensure your security strategy addresses the following areas:
Practical review checklist
- Scantide Online reviews website security headers such as HSTS, CSP, X-Frame-Options and related browser controls in the context of the public site.
- Use Scantide Online to check DNS and mail security, HTTPS/TLS, security headers, cookies and public infrastructure context from one domain scan.
- Use Scantide Online to review public hosts, HTTPS, headers, DNS and infrastructure evidence for a readable first-pass public server security assessment.
- Scantide Online reviews public DNS, mail-security records, HTTP/HTTPS behavior, TLS, security headers, cookies, infrastructure and CVE-related context to provide a readable external assessment of a domain.
- Scantide Online checks public DNS and mail-security signals including SPF and DMARC as part of a broader external domain assessment.
- Disbling compatibiliy check when opening 2003 .xls in @Office 2007 impossible.
- This automated scanner focuses on infrastructure vulnerabilities, exposed services, and configuration issues.