49 scored controls

Security remediation guides

Use the check ID from a SecuTest report to locate the corresponding operational guide.

Attack surface

1 guides

Certificate security

2 guides

DNS security

4 guides

Email security

25 guides
Email security DKIM CNAME chain A broken, looping, or excessively long DKIM CNAME chain can prevent receivers from retrieving the signing key. Open remediation guide → Email security DKIM public key presence A DKIM record without an active public key cannot validate signatures and may represent an incomplete or unintended revocation. Open remediation guide → Email security DKIM public key strength A weak DKIM key may not provide adequate resistance to key recovery or forgery over the intended lifetime. Open remediation guide → Email security DKIM record syntax Malformed DKIM tags can make an otherwise published key unusable and cause signature verification failures. Open remediation guide → Email security DKIM testing flag Leaving the DKIM testing flag enabled can signal that verification failures should be treated less strictly than intended. Open remediation guide → Email security DMARC aggregate reporting A weakness in dmarc aggregate reporting can reduce the reliability of the domain's external security controls. Open remediation guide → Email security DMARC enforcement percentage A weakness in dmarc enforcement percentage can reduce the reliability of the domain's external security controls. Open remediation guide → Email security DMARC enforcement policy A weakness in dmarc enforcement policy can reduce the reliability of the domain's external security controls. Open remediation guide → Email security DMARC record presence A weakness in dmarc record presence can reduce the reliability of the domain's external security controls. Open remediation guide → Email security DMARC subdomain policy A weakness in dmarc subdomain policy can reduce the reliability of the domain's external security controls. Open remediation guide → Email security Duplicate DKIM records Multiple conflicting DKIM records for one selector can make key retrieval ambiguous and cause verification failures. Open remediation guide → Email security Null MX configuration A weakness in null mx configuration can reduce the reliability of the domain's external security controls. Open remediation guide → Email security Resolvable DKIM selector A configured selector that does not resolve prevents recipients from retrieving the public key needed to verify DKIM signatures. Open remediation guide → Email security Resolvable MX targets A weakness in resolvable mx targets can reduce the reliability of the domain's external security controls. Open remediation guide → Email security SPF DNS lookup limit A weakness in spf dns lookup limit can reduce the reliability of the domain's external security controls. Open remediation guide → Email security SPF PTR mechanism A weakness in spf ptr mechanism can reduce the reliability of the domain's external security controls. Open remediation guide → Email security SPF all mechanism policy A weakness in spf all mechanism policy can reduce the reliability of the domain's external security controls. Open remediation guide → Email security SPF include and redirect recursion A weakness in spf include and redirect recursion can reduce the reliability of the domain's external security controls. Open remediation guide → Email security SPF record presence A weakness in spf record presence can reduce the reliability of the domain's external security controls. Open remediation guide → Email security Single DMARC record A weakness in single dmarc record can reduce the reliability of the domain's external security controls. Open remediation guide → Email security Single SPF record A weakness in single spf record can reduce the reliability of the domain's external security controls. Open remediation guide → Email security Valid DKIM public key An invalid DKIM key cannot be used by receivers to verify message signatures. Open remediation guide → Email security Valid DMARC syntax A weakness in valid dmarc syntax can reduce the reliability of the domain's external security controls. Open remediation guide → Email security Valid MX record syntax A weakness in valid mx record syntax can reduce the reliability of the domain's external security controls. Open remediation guide → Email security Valid SPF syntax A weakness in valid spf syntax can reduce the reliability of the domain's external security controls. Open remediation guide →

Reputation

2 guides

Transport security

6 guides

Web security

9 guides
Web security Clickjacking protection A weakness in clickjacking protection can reduce the reliability of the domain's external security controls. Open remediation guide → Web security Content Security Policy A weakness in content security policy can reduce the reliability of the domain's external security controls. Open remediation guide → Web security HTTP Strict Transport Security A weakness in http strict transport security can reduce the reliability of the domain's external security controls. Open remediation guide → Web security HTTP to HTTPS redirect A weakness in http to https redirect can reduce the reliability of the domain's external security controls. Open remediation guide → Web security HTTPS availability A weakness in https availability can reduce the reliability of the domain's external security controls. Open remediation guide → Web security Permissions Policy A weakness in permissions policy can reduce the reliability of the domain's external security controls. Open remediation guide → Web security Referrer Policy A weakness in referrer policy can reduce the reliability of the domain's external security controls. Open remediation guide → Web security Server software disclosure A weakness in server software disclosure can reduce the reliability of the domain's external security controls. Open remediation guide → Web security X-Content-Type-Options A weakness in x-content-type-options can reduce the reliability of the domain's external security controls. Open remediation guide →