Coverage and remediation resources

Know what the scanner checks—and what each result means

Review the current code-owned Safe External v1 coverage, then use practical DNS, TLS, and HTTP guides to investigate and verify changes.

Safe External v1

Code-owned baseline

Checks
5
Families
3
Guides
6

Coverage shown here is profile-specific and is not a claim of exhaustive vulnerability detection.

Current coverage

The code-owned baseline, row by row

A check can pass, produce a bounded error, or create a trusted finding. The table states that behavior explicitly.

DNSdns.public-addresses
Observed
Fresh A/AAAA resolution and public-destination eligibility before connection
Result behavior
Pass or bounded safety error; no retained vulnerability finding
Read guide
DNSdns.caa
Observed
Presence of a CAA policy for a domain target
Result behavior
Informational finding when no CAA record is observed
Read guide
TLStls.certificate
Observed
Trust chain, authorized-hostname coverage, and remaining certificate lifetime
Result behavior
Critical invalid-certificate or high expiring-soon finding
Read guide
HTTPhttp.https-redirect
Observed
Root HTTP response upgrades the same authorized host to HTTPS
Result behavior
Medium finding when the approved same-host upgrade is absent
Read guide
HTTPhttp.security-headers
Observed
Presence of HSTS, CSP, and X-Content-Type-Options on the bounded HTTPS response
Result behavior
Medium finding naming one or more missing supported headers
Read guide
Remediation library

Six focused guides for the current baseline

Each guide separates observation, investigation, remediation, verification, and limitations.

DNS

Public DNS address validation

How fresh A and AAAA resolution keeps an authorized external scan on public destinations—and what this safety check does not assess.

Read the guide
DNS

CAA record checks

Understand a missing CAA policy, decide which certificate authorities should be named, and verify the published DNS change.

Read the guide
TLS

TLS certificate validation

Investigate certificate trust or hostname validation failures and verify a complete, correctly scoped replacement deployment.

Read the guide
TLS

TLS certificate expiration

Respond to the Safe External 30-day warning window and confirm that renewal automation delivered the right certificate everywhere.

Read the guide
HTTP

HTTP to HTTPS redirects

Configure and verify a same-host HTTPS upgrade so visitors who begin with HTTP are not left on an unencrypted connection.

Read the guide
HTTP

HTTP security headers

Plan and verify HSTS, Content-Security-Policy, and X-Content-Type-Options without treating header presence as complete browser security.

Read the guide

A baseline with explicit boundaries

Safe operation and accurate interpretation matter as much as a list of checks.

  • No destructive checks, denial-of-service behavior, broad brute force, fuzzing, or indiscriminate port scanning.
  • No claim that a completed scan proves an asset is vulnerability-free.
  • No replacement for a separately scoped penetration test, internal assessment, or compliance audit.
  • No storage of response bodies, raw headers, cookies, secrets, certificates, or raw scanner output in the trusted result path.

Review the scanning policy

See how authorization, destination validation, evidence bounds, and emergency controls constrain execution.

Read the security policy

See a report workflow

Explore a clearly labeled fictional report with findings, remediation status, and limitations.

View the sample report
Know what is exposed.
Know what is exposed.

Your first scan is one verified domain away

Three assets free for 14 days. No card required.

Start free