Valid certificate, expires in 68 days, auto-renews. Visitors see the padlock.
Your site forces secure connections — browsers refuse to load it over insecure HTTP.
Your domain declares which servers may send email as you. Cuts down on spoofing.
No anti-spoofing policy set. Scammers could send fake emails using your name. High priority — see below.
Your outgoing email is cryptographically signed, so inboxes trust it's really you.
Two recommended headers missing (X-Frame-Options, Referrer-Policy). Low risk, quick to add.
No content-security policy. Adds a guardrail against injected/malicious scripts.
Every image, script and font loads over HTTPS. No insecure "this page is not fully secure" warnings.
Cookies set with Secure + HttpOnly flags, so they can't leak over insecure connections.
No sensitive files (.env, .git, backups, admin) reachable from the open web.
3 subdomains found (mail, dev, staging). "dev" shows a login page — consider hiding it from the public.
Only web ports (80/443) are open. No database or admin ports exposed to the internet.
Think of it like a building inspection. Doors, locks and wiring (your SSL, email signing, open ports) are solid. The one real gap is your mailbox sign: without DMARC, anyone can put your name on an envelope. For a trades business that emails invoices and quotes, that's worth closing — a scammer impersonating "Acme Plumbing" to your customers is a reputation risk, not just a technical one. The two warnings are nice-to-haves you can do later. Your AI helper can hand your host the exact records to paste in.