What Hardenize measures
The report covers DNS configuration and DNSSEC, the certificate and TLS setup, HTTP security headers, and email security records including SPF, DKIM and DMARC. Everything lands on one page with a coloured status per row.
How to read your result
The email section is the part most site owners have never looked at. A missing or misconfigured SPF or DMARC record is why legitimate email from your domain lands in spam, and it also leaves your domain open to being forged by someone else. DNSSEC being absent is common and not urgent.
What to change first
If DMARC is missing, add a monitoring only record first. It changes nothing about delivery and starts sending you reports on who is sending mail as your domain, which is the information you need before enforcing anything.
Common questions
- What is DMARC and do I need it?
- DMARC tells receiving mail servers what to do with email that fails authentication as your domain. Without it, anyone can forge your address more easily, and some providers now require it for bulk senders.
- Does Hardenize check my website or my domain?
- The whole domain, including DNS and email, which is why it finds things a page level scanner cannot.
Related tests
Run this alongside every other test in Website Security Checks, or start from the full list of website testing tools.
