SecuTest knowledge base
From security finding to verified remediation
Every guide explains the finding, gives an immediate first action, identifies where to change the configuration, provides commands and deployment steps, warns about common mistakes, and ends with an external verification workflow.
Scan a domain49 scored controls
Security remediation guides
Use the check ID from a SecuTest report to locate the corresponding operational guide.
Attack surface
1 guidesCertificate security
2 guides
Certificate security
CAA issuance policy
An absent or overly broad CAA policy gives no DNS-level restriction on which certificate authorities may issue for the domain.
Open remediation guide →
Certificate security
CAA record syntax
Malformed CAA records may be ignored or cause certificate issuance behavior that differs from the intended policy.
Open remediation guide →
DNS security
4 guides
DNS security
DNSSEC algorithm strength
Deprecated DNSSEC algorithms can reduce cryptographic assurance and create interoperability or policy failures.
Open remediation guide →
DNS security
DNSSEC validation
Broken or absent DNSSEC validation can leave DNS answers without cryptographic authenticity or make a signed zone unreachable to validating resolvers.
Open remediation guide →
DNS security
Dangling DNS records
A DNS record that points to an unclaimed external resource may allow another party to control content under your domain.
Open remediation guide →
DNS security
Subdomain takeover risk
A claimable third-party target can let an attacker publish content, obtain trust, and abuse cookies or links under your domain.
Open remediation guide →
Email security
25 guides
Email security
DKIM CNAME chain
A broken, looping, or excessively long DKIM CNAME chain can prevent receivers from retrieving the signing key.
Open remediation guide →
Email security
DKIM public key presence
A DKIM record without an active public key cannot validate signatures and may represent an incomplete or unintended revocation.
Open remediation guide →
Email security
DKIM public key strength
A weak DKIM key may not provide adequate resistance to key recovery or forgery over the intended lifetime.
Open remediation guide →
Email security
DKIM record syntax
Malformed DKIM tags can make an otherwise published key unusable and cause signature verification failures.
Open remediation guide →
Email security
DKIM testing flag
Leaving the DKIM testing flag enabled can signal that verification failures should be treated less strictly than intended.
Open remediation guide →
Email security
DMARC aggregate reporting
A weakness in dmarc aggregate reporting can reduce the reliability of the domain's external security controls.
Open remediation guide →
Email security
DMARC enforcement percentage
A weakness in dmarc enforcement percentage can reduce the reliability of the domain's external security controls.
Open remediation guide →
Email security
DMARC enforcement policy
A weakness in dmarc enforcement policy can reduce the reliability of the domain's external security controls.
Open remediation guide →
Email security
DMARC record presence
A weakness in dmarc record presence can reduce the reliability of the domain's external security controls.
Open remediation guide →
Email security
DMARC subdomain policy
A weakness in dmarc subdomain policy can reduce the reliability of the domain's external security controls.
Open remediation guide →
Email security
Duplicate DKIM records
Multiple conflicting DKIM records for one selector can make key retrieval ambiguous and cause verification failures.
Open remediation guide →
Email security
Null MX configuration
A weakness in null mx configuration can reduce the reliability of the domain's external security controls.
Open remediation guide →
Email security
Resolvable DKIM selector
A configured selector that does not resolve prevents recipients from retrieving the public key needed to verify DKIM signatures.
Open remediation guide →
Email security
Resolvable MX targets
A weakness in resolvable mx targets can reduce the reliability of the domain's external security controls.
Open remediation guide →
Email security
SPF DNS lookup limit
A weakness in spf dns lookup limit can reduce the reliability of the domain's external security controls.
Open remediation guide →
Email security
SPF PTR mechanism
A weakness in spf ptr mechanism can reduce the reliability of the domain's external security controls.
Open remediation guide →
Email security
SPF all mechanism policy
A weakness in spf all mechanism policy can reduce the reliability of the domain's external security controls.
Open remediation guide →
Email security
SPF include and redirect recursion
A weakness in spf include and redirect recursion can reduce the reliability of the domain's external security controls.
Open remediation guide →
Email security
SPF record presence
A weakness in spf record presence can reduce the reliability of the domain's external security controls.
Open remediation guide →
Email security
Single DMARC record
A weakness in single dmarc record can reduce the reliability of the domain's external security controls.
Open remediation guide →
Email security
Single SPF record
A weakness in single spf record can reduce the reliability of the domain's external security controls.
Open remediation guide →
Email security
Valid DKIM public key
An invalid DKIM key cannot be used by receivers to verify message signatures.
Open remediation guide →
Email security
Valid DMARC syntax
A weakness in valid dmarc syntax can reduce the reliability of the domain's external security controls.
Open remediation guide →
Email security
Valid MX record syntax
A weakness in valid mx record syntax can reduce the reliability of the domain's external security controls.
Open remediation guide →
Email security
Valid SPF syntax
A weakness in valid spf syntax can reduce the reliability of the domain's external security controls.
Open remediation guide →
Reputation
2 guides
Reputation
Domain blocklist reputation
A domain listed by a reputable blocklist may experience email rejection, browser warnings, or loss of trust and can indicate abuse or compromise.
Open remediation guide →
Reputation
IP blocklist reputation
A public IP listed for spam, malware, or compromised-host activity can disrupt email delivery and indicate active abuse.
Open remediation guide →
Transport security
6 guides
Transport security
Modern TLS protocol version
A weakness in modern tls protocol version can reduce the reliability of the domain's external security controls.
Open remediation guide →
Transport security
Obsolete TLS protocols
Support for TLS 1.0 or TLS 1.1 exposes clients to obsolete protocol behavior and may violate modern security baselines.
Open remediation guide →
Transport security
TLS certificate expiration
A weakness in tls certificate expiration can reduce the reliability of the domain's external security controls.
Open remediation guide →
Transport security
TLS certificate validation
A weakness in tls certificate validation can reduce the reliability of the domain's external security controls.
Open remediation guide →
Transport security
TLS service availability
A weakness in tls service availability can reduce the reliability of the domain's external security controls.
Open remediation guide →
Transport security
Weak TLS cipher suites
Accepted NULL, EXPORT, RC4, DES, 3DES, MD5, or anonymous suites materially weaken confidentiality or authentication.
Open remediation guide →
Web security
9 guides
Web security
Clickjacking protection
A weakness in clickjacking protection can reduce the reliability of the domain's external security controls.
Open remediation guide →
Web security
Content Security Policy
A weakness in content security policy can reduce the reliability of the domain's external security controls.
Open remediation guide →
Web security
HTTP Strict Transport Security
A weakness in http strict transport security can reduce the reliability of the domain's external security controls.
Open remediation guide →
Web security
HTTP to HTTPS redirect
A weakness in http to https redirect can reduce the reliability of the domain's external security controls.
Open remediation guide →
Web security
HTTPS availability
A weakness in https availability can reduce the reliability of the domain's external security controls.
Open remediation guide →
Web security
Permissions Policy
A weakness in permissions policy can reduce the reliability of the domain's external security controls.
Open remediation guide →
Web security
Referrer Policy
A weakness in referrer policy can reduce the reliability of the domain's external security controls.
Open remediation guide →
Web security
Server software disclosure
A weakness in server software disclosure can reduce the reliability of the domain's external security controls.
Open remediation guide →
Web security
X-Content-Type-Options
A weakness in x-content-type-options can reduce the reliability of the domain's external security controls.
Open remediation guide →