Security Checks
Understand what WebInspect checks and why it matters
WebInspect examines your website and domain from an external perspective, looking for security configuration issues across HTTPS, SSL/TLS, HTTP security headers, DNS, email authentication and other publicly visible security controls.
Our automated inspection is designed to give website owners, businesses, developers and IT professionals a clearer understanding of the security posture their website presents to the Internet.
Explore the checks below to learn what WebInspect looks for, why each area matters and what the results can tell you about your website.
A website can appear to be working perfectly while still having security configuration issues that are invisible during normal browsing.
The WebInspect security scan combines multiple external checks into a single inspection, examining areas such as HTTPS, SSL/TLS, security headers, domain configuration, email authentication and publicly exposed information.
It provides a practical starting point for understanding your website's externally visible security posture.
Learn about the Free Website Security ScannerHTTP security headers allow your website to instruct browsers how content should be handled and which security restrictions should be enforced.
WebInspect checks for important browser security controls including Content Security Policy (CSP), HTTP Strict Transport Security (HSTS), X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy.
Missing or incorrectly configured security headers do not necessarily mean that a website is vulnerable, but they can indicate that useful browser-side protections are not being fully utilized.
Learn about Security Header ChecksHTTPS protects information transmitted between your website and its visitors.
WebInspect examines your website's externally visible SSL/TLS configuration, including HTTPS availability, certificate information, certificate expiration and supported TLS protocol versions.
The inspection can help identify issues such as outdated TLS protocol support, certificate problems and HTTPS configuration that may require further review.
Learn about SSL/TLS Security ChecksWebsite security does not stop at the web server. Your domain's email configuration can also play an important role in protecting your organization and its users.
DMARC works alongside SPF and DKIM to help receiving email systems determine whether messages claiming to originate from your domain have been properly authenticated.
WebInspect checks publicly available email authentication information to help identify missing or potentially weak domain email security configuration.
Learn about DMARC ChecksSome externally visible website security controls can be relevant when reviewing an organization's security posture in relation to PCI DSS.
WebInspect examines applicable technical indicators such as HTTPS, TLS configuration, certificate status, security headers and other externally observable security settings.
These checks can help highlight areas that may deserve attention when preparing for or maintaining a secure environment.
WebInspect's PCI DSS readiness information is not a PCI DSS certification, ASV scan or formal determination of compliance.
Learn about PCI DSS Security ReadinessSecurity configuration is rarely as simple as checking whether a setting exists.
A particular header may be present but configured incorrectly. A TLS certificate may be valid while the server still supports an outdated protocol. A DMARC record may exist but use a monitoring policy rather than enforcement.
For this reason, WebInspect is designed to provide context around detected findings rather than treating every security control as a simple checkbox.
Depending on the report selected, additional technical details and remediation guidance can help you understand what was detected and what may need attention.
WebInspect performs its inspection from outside your environment without requiring administrative access to your website or server.
This provides a useful view of the security configuration and information that your website presents publicly to Internet users.
However, an external unauthenticated inspection cannot evaluate every aspect of website security.
WebInspect does not replace authenticated vulnerability assessments, penetration testing, source-code reviews, internal security audits or formal compliance assessments.
Instead, it provides an accessible way to identify externally observable security issues and opportunities for improvement.
Want to see how your website performs across these security checks?
Enter your domain to receive a free security snapshot with no account required. Your website will be inspected from an external perspective and the results will highlight security controls that passed as well as areas that may need attention.
Run a Free Website Security Scan