Understand your public risk
Start with the visible signals customers, browsers, email providers, vendors, and insurers can already see.
Use the checklistCybersecurity Center
Learn what to check, why it matters, and when website, email, DNS, or admin-access issues need a vendor-ready fix order instead of more guessing.
Built for owners who rely on a public website, branded email, Google Workspace or Microsoft 365, booking tools, payment links, vendors, and customer trust.
Practical guidance
CyberBit focuses on practical website, email, domain, cloud-account, and cybersecurity foundation support for small businesses. The goal is to identify owner-actionable risks and give providers clear next steps.
This hub is educational, but it is not generic blog filler. Each section points back to a business decision: what can you check yourself, what should a provider fix, and when is the $199 Snapshot the cleaner first paid step?
Tool directory
These tools are educational visibility checks. They do not perform exploit testing, malware scanning, credential testing, or compliance certification.
Website, DNS, email, TLS, and headers
Run the main public-signal check for a business domain. Results explain visible website, email-authentication, TLS, and security-header basics.
Run the free checkMX, SPF, DMARC, MTA-STS, TLS-RPT, and DNSSEC
Review public email-trust records and validate a published MTA-STS policy without treating an unknown DKIM selector as a failed control.
Check email trustBrowser-only ownership handoff checklist
Confirm who controls the domain, DNS, website, workspace, recovery methods, vendors, backups, and emergency contacts.
Review ownershipPublic IP, browser signals, WebRTC, and before/after comparison
Review browser-visible connection evidence and compare factual changes after switching VPN, Wi-Fi, hotspot, or network, without a fake DNS-leak verdict.
Check connection signalsExplainer directory
Use these explainers to understand results before asking a provider to make changes.
Understand HSTS, CSP, frame protection, MIME sniffing protection, Referrer-Policy, Permissions-Policy, CORS, COOP, COEP, and CORP.
Learn what HTTPS, TLS versions, certificate expiration, OCSP, redirects, and HSTS mean for a small-business website.
Review SPF, DKIM, DMARC, alignment, spoofing risk, and why email changes should be staged carefully.
Understand registrar, registry, privacy, DNSSEC, renewal, auto-renew, and ownership handoff questions.
Learn the difference between DNS resolvers, encrypted DNS, VPN DNS, WebRTC, ICE candidates, mDNS, STUN, and TURN.
Know what websites may see about your current connection and why VPN, proxy, mobile, and office networks can look different.
Start here
Use this page to understand the basics, run a safe public check, and decide whether you need a paid review, cleanup help, monitoring, or questionnaire support.
Start with the visible signals customers, browsers, email providers, vendors, and insurers can already see.
Use the checklistUse the free public check for a quick look at HTTPS, redirects, security headers, DNS, SPF, and DMARC indicators.
Run free public checkIf you want CyberBit to review the signals and give you a fix order, use the Website, Email & Domain Security Snapshot and compare the sample report.
Start $199 SnapshotCommon small-business risks
These checks are practical starting points, not guarantees. They help owners spot hidden setup issues and decide whether a Snapshot, cleanup sprint, service provider, or internal follow-up is needed.
Risk area
Attackers may try to send fake invoices, payment changes, or vendor messages that appear to come from your domain.
What to check
The Snapshot explains visible email-authentication gaps and turns them into vendor-ready next steps.
Review related guidanceRisk area
Missing or inconsistent DNS, HTTPS, redirect, and browser-header settings can make a site harder to trust and harder to hand off.
What to check
The Snapshot separates quick public-signal fixes from items that need a web host, DNS provider, or developer.
Review related guidanceRisk area
Old pages, exposed forms, unsafe redirects, or unclear platform ownership can create business risk before anyone contacts you.
What to check
The Snapshot gives a practical website-risk summary and points to cleanup, redesign, takeover, or vendor handoff when needed.
Review related guidanceRisk area
Admin accounts, shared passwords, unmanaged MFA, and old vendor access often create the easiest path into critical business systems.
What to check
The Snapshot flags public-facing ownership and admin-risk questions to resolve before deeper cleanup.
Review related guidanceRisk area
Outdated CMS, plugin, theme, booking, or form platforms can turn a small website issue into a larger cleanup or takeover project.
What to check
The Snapshot helps decide whether the right next step is simple cleanup, a secure redesign, or a focused takeover sprint.
Review related guidanceRisk area
Client, insurer, and vendor questionnaires can create risk when answers claim controls that are not actually in place.
What to check
The Snapshot creates a cleaner fact base before a questionnaire or a separate Client/Vendor Security Questionnaire Support engagement.
Review related guidanceRisk area
Small businesses often lose time during an incident because account ownership, backups, contacts, and provider responsibilities are unclear.
What to check
The Snapshot is not incident response, but it gives a practical prevention roadmap and a clearer fix order.
Review related guidanceStart with your question
This navigator uses existing guides, free checks, and service routes. It keeps personal concerns separate from business requests and does not route every question to the Snapshot.
Selected topic
Understand public website, HTTPS, browser-header, form, and ownership basics.
1. Learn
Read Website & Domain Security2. Check
Run the free public check3. Get help
View focused CleanupBrowse the full topic library
Pick a category, jump to a topic, and start with the checks that reduce practical business risk first.
28 practical topics available. Use the filters to narrow by area.
Email Security
Reduce the chance that criminals can impersonate your domain, abuse business email, or trick staff and customers.
Why it matters
Email compromise and domain spoofing can lead to invoice fraud, fake messages, and lost trust.
Who should review it
Businesses that send email from their own domain or rely on Microsoft 365 / Google Workspace.
What to check
When to ask for help
Email Security
These email authentication records help receiving mail systems decide whether messages using your domain are allowed and trustworthy.
Why it matters
Weak or missing authentication can make spoofing, invoice fraud, and questionnaire follow-up harder to manage.
Who should review it
Businesses that send email from a company domain through Microsoft 365, Google Workspace, marketing tools, invoicing systems, or website forms.
What to check
When to ask for help
Email Security
DMARC helps domain owners tell receiving mail systems what to do when someone tries to send email that fails SPF or DKIM checks. For small businesses, it is one of the clearest public signals that business email has been reviewed.
Why it matters
Weak or missing DMARC can make it easier for criminals to spoof a domain and send fake invoices, vendor messages, or staff impersonation emails.
Who should review it
Businesses using Microsoft 365, Google Workspace, or any service that sends email from the company domain.
What to check
When to ask for help
Website Security
Keep your public website, contact forms, booking links, and trust signals from becoming easy business risk.
Why it matters
Website and domain gaps can create trust issues before a customer, patient, or client ever calls.
Who should review it
Businesses with websites, contact forms, booking pages, payment links, or client intake forms.
What to check
When to ask for help
Website Security
Security headers are browser instructions that help reduce common website risks such as clickjacking, unsafe content loading, MIME sniffing, and overly broad browser permissions.
Why it matters
Headers do not make a site invincible, but missing or weak headers are visible signals that a site may need safer browser-side defaults.
Who should review it
Businesses with public websites, booking pages, client portals, forms, or embedded third-party tools.
What to check
When to ask for help
Website Security
HTTPS is the secure browser connection people expect before submitting forms, booking appointments, or trusting a business website.
Why it matters
Broken HTTPS, mixed content, or missing redirects can make a legitimate website look unsafe and can confuse customers or providers.
Who should review it
Any business with a public website, contact form, booking flow, payment link, or customer intake path.
What to check
When to ask for help
Foundations
DNS records route website, email, verification, and vendor services. Owners should know who can change them and why each record exists.
Why it matters
Unclear DNS ownership can delay security fixes, email changes, website launches, and vendor handoffs.
Who should review it
Businesses that inherited a domain, changed vendors, use multiple marketing/email tools, or are not sure where DNS is hosted.
What to check
When to ask for help
Foundations
WHOIS and registrar information can help owners understand who manages a domain, when it renews, and whether privacy, DNSSEC, and contact details need review.
Why it matters
Domain ownership problems can interrupt website and email service, delay DNS changes, and make vendor handoff harder.
Who should review it
Businesses that inherited a domain, switched vendors, missed renewal notices, or are unsure who controls the registrar account.
What to check
When to ask for help
Foundations
Browser and network checks can show what websites may see about your current connection, including public IP, IP version, and browser-exposed WebRTC candidates.
Why it matters
These signals do not prove anonymity, but they help users understand whether a network change appears to be visible to websites.
Who should review it
Owners and staff who use VPNs, remote work networks, shared Wi-Fi, hotspots, or browsers with WebRTC enabled.
What to check
When to ask for help
Foundations
A public IP is the network address websites see. It may be IPv4, IPv6, a VPN/proxy address, a mobile network, or a carrier-grade NAT address managed by an ISP.
Why it matters
Knowing what IP version and network are visible helps owners avoid confusing a normal provider change with a security issue.
Who should review it
Anyone troubleshooting VPNs, remote work, office networks, website allowlists, provider tickets, or suspicious sign-in alerts.
What to check
When to ask for help
Access Control
Reduce risk from exposed admin paths, old vendor access, weak MFA coverage, and unclear account ownership.
Why it matters
A small number of overpowered accounts often control the website, email, DNS, payments, forms, and customer communication.
Who should review it
Businesses with website admins, domain/DNS admins, payment tools, cloud accounts, booking systems, former staff, or outside vendors.
What to check
When to ask for help
Website Security
Review CMS, plugin, theme, form, booking, payment-link, and website platform exposure before small maintenance gaps become cleanup projects.
Why it matters
Outdated website components and unmanaged integrations can create trust, maintenance, and security problems that are harder to fix during a vendor handoff.
Who should review it
Businesses using WordPress, website builders, booking widgets, form plugins, marketing scripts, payment links, or vendor-managed sites.
What to check
When to ask for help
Website Security
Contact, booking, newsletter, quote, and intake forms should collect only needed information and reduce automated abuse without blocking real customers.
Why it matters
Poor form handling can flood inboxes, expose sensitive requests, or train staff to ignore legitimate messages.
Who should review it
Businesses with public forms, booking widgets, quote forms, newsletters, lead magnets, or customer intake pages.
What to check
When to ask for help
Access Control
The registrar controls the domain registration and can affect the website, email, DNS, renewal, and ownership recovery path.
Why it matters
A lost or compromised registrar account can interrupt website and email operations or make recovery difficult.
Who should review it
Owners, office managers, web vendors, and IT providers responsible for domain renewal or domain-level changes.
What to check
When to ask for help
Vendor Risk
Prepare a supportable Client/Vendor Security Questionnaire Support Package when a client, customer, partner, or vendor due-diligence team asks about security controls. Insurance applications and renewals use the separate Cyber Insurance Evidence Review.
Why it matters
Unsupported questionnaire answers can create business risk and follow-up work if evidence does not match reality.
Who should review it
Businesses that use software vendors, payment processors, booking tools, IT providers, marketing agencies, payroll platforms, or outsourced staff.
What to check
When to ask for help
Insurance Readiness
Plain-English guidance on common cyber insurance application topics such as MFA, backups, email authentication, admin access, and vendor documentation. This is not legal, insurance, or compliance advice.
Why it matters
Owners need to understand what insurers commonly ask for before claiming controls or submitting unsupported answers.
Who should review it
Small businesses preparing for cyber insurance applications, renewals, broker questions, or insurer follow-up requests.
What to check
When to ask for help
Foundations
A practical starting point for deciding what to review first when everything feels important.
Why it matters
Owners need a short, defensible fix order before spending time or money on deeper security work.
Who should review it
Every small business with email, a website, online payments, client records, or cloud accounts.
What to check
When to ask for help
Website Security
Security and ownership basics to include when rebuilding an outdated or confusing small-business website.
Why it matters
A redesign is the best time to clean up SSL/TLS, forms, admin access, domain/DNS ownership, and vendor handoff before old issues are rebuilt into the new site.
Who should review it
Businesses replacing a website, changing platforms, adding forms, or hiring a new web vendor.
What to check
When to ask for help
Foundations
A plain-English checklist for identifying who controls the domain, DNS, email provider, senders, and account recovery paths.
Why it matters
When ownership is unclear, website, email, and security fixes take longer and can become risky during vendor transitions.
Who should review it
Owners who inherited a website, changed vendors, or are not sure where DNS and email settings live.
What to check
When to ask for help
Foundations
A checklist for taking over from a web, DNS, email, marketing, or IT provider without guessing who owns what.
Why it matters
A clean handoff reduces lockout risk and makes the next provider conversation more concrete.
Who should review it
Businesses switching vendors, recovering from poor handoff, or cleaning up a messy existing setup.
What to check
When to ask for help
Cloud Accounts
Tighten the basic account and sharing controls around the cloud workspace where your daily work happens, with a focused Workspace Security Baseline Report when you need help.
Why it matters
A compromised cloud account can expose client records, invoices, contracts, employee data, and internal files.
Who should review it
Businesses using Microsoft 365, Outlook, Gmail, Google Workspace, SharePoint, OneDrive, or Google Drive.
What to check
When to ask for help
Scam Prevention
Build simple habits that help owners and staff slow down suspicious invoices, links, texts, and urgent requests.
Why it matters
Payment-change scams and fake login messages can move quickly if staff do not have a simple verification habit.
Who should review it
Owners, office managers, finance staff, receptionists, and anyone who handles email, invoices, texts, or calls.
What to check
When to ask for help
Resilience
Make sure important business files can be restored after deletion, device loss, account compromise, or ransomware.
Why it matters
Recovery planning keeps a bad day from becoming a long business interruption.
Who should review it
Businesses that store documents, customer records, invoices, images, contracts, schedules, or operational files.
What to check
When to ask for help
Access Control
Reduce risk from old accounts, shared passwords, overpowered admin access, and unmanaged staff changes.
Why it matters
Old accounts, shared passwords, weak passwords, and unnecessary admin access create easy entry points.
Who should review it
Any business with employees, contractors, vendors, shared accounts, or former staff.
What to check
When to ask for help
Scam Prevention
Protect the owner and key decision-makers whose personal email, phone, and recovery settings often control business access.
Why it matters
Owner account compromise can affect business email, banking, domain access, social media, and customer communication.
Who should review it
Owners, partners, office managers, and family members who control business accounts, payments, devices, or recovery emails.
What to check
When to ask for help
Resilience
Keep website, domain, email, and public-facing security signals from drifting after a Snapshot, cleanup, rebuild, takeover, or agreed baseline.
Why it matters
Basic security hygiene can drift when domains, email tools, websites, vendors, and staff access change over time.
Who should review it
Small businesses that want scoped monthly website and public-facing security oversight without buying a full MSP, helpdesk, SOC, or MDR.
What to check
When to ask for help
Resilience
Owners should know what to do first when an account, email, domain, or website looks suspicious, and when CyberBit's standard services are not emergency incident response.
Why it matters
Clear boundaries prevent delayed emergency action and keep routine cleanup separate from active incident handling.
Who should review it
Businesses seeing suspicious inbox rules, unknown admin users, payment-change messages, website defacement, or provider alerts.
What to check
When to ask for help
Foundations
A safe handoff gives the right provider enough context to fix website, email, DNS, and account issues without passing secrets around casually.
Why it matters
Clean handoff notes reduce lockout risk, duplicated work, and unsupported changes to critical settings.
Who should review it
Businesses switching web vendors, IT providers, marketing agencies, website platforms, or email providers.
What to check
When to ask for help
Risk check vs paid Snapshot
The Free Website, Email & Domain Check is useful for public basics. The Snapshot is for owners who want CyberBit to review the 11 areas, explain what matters, and create a prioritized fix order.
Quick public-signal check
Paid prioritized review
Next steps
The Snapshot is the default paid diagnostic. Use services, cleanup, or contact when you already know what needs to happen or have a deadline-driven request.
Best first paid step when you want a plain-English report, prioritized findings, and vendor-ready next steps.
Preview the type of findings, business-risk explanations, and recommended fix order CyberBit provides.
Compare the $750 cleanup path, Business Security Remediation Sprint From $1,500, External Security Watch $99/month or From $499/month, and questionnaire support.
Use this when you already know the gaps and need implementation, provider coordination, or cleanup documentation.
Contact CyberBit when you have a deadline, vendor question, insurance request, or are unsure which service fits.
Need questionnaire-specific support? Client/Vendor Security Questionnaire Support — From $1,500. Need ongoing public-signal oversight after fixes? View External Security Watch.
What to check first
This is a plain-English starting point, not a full audit. It helps you organize website, email, domain, admin, and vendor questions before asking someone to make changes.
Is the website reachable over HTTPS?
Does HTTP redirect visitors to HTTPS?
Are basic browser security headers present?
Are SPF and DMARC present for the sending domain?
Is DMARC only monitoring, or is it moving toward enforcement after review?
Do you know who controls DNS and the domain registrar?
Are admin/login pages intentionally public and protected?
Is MFA enabled for domain, email, website, and cloud administrator accounts?
Do you know who can change website, email, DNS, form, and payment-link settings?
Can you explain the setup to a client, vendor, insurer, or security questionnaire reviewer?
Do you have a clean fix order before asking a provider to make changes?
Common problems by business type
These are practical examples, not client claims or guarantees. Use them to decide where to start.
Common risk
Patient-facing forms, online scheduling, email, and vendor portals often depend on multiple providers.
Why it matters
Ownership confusion can slow down secure fixes and make insurance or vendor questions harder to answer.
Start with the Free Website, Email & Domain Check or Website, Email & Domain Security Snapshot, then use cleanup help if website/email/DNS changes are needed.
Start $199 SnapshotCommon risk
Email spoofing, document sharing, client portals, and vendor questionnaires can create trust and evidence gaps.
Why it matters
Clients may ask for clear answers about MFA, backups, email authentication, access, and provider controls.
Review DMARC and admin access first, then compare Client/Vendor Security Questionnaire Support if a client request is active.
View questionnaire supportCommon risk
A basic website, branded email, booking forms, and payment-change messages can all affect customer trust.
Why it matters
Missing HTTPS, weak email authentication, or old vendor access can make scams and handoff problems more likely.
Use the public check for quick signals, then request Focused Security Cleanup if fixes are already clear.
View cleanup serviceCommon risk
Plugins, redirects, forms, checkout links, tracking scripts, and admin access can drift as tools change.
Why it matters
A small website change can affect customer confidence, payment flow, and vendor handoff notes.
Use the Snapshot for a prioritized review before cleanup, redesign, or provider coordination.
Start $199 SnapshotCommon risk
Shared admin access, volunteer turnover, donation links, and old web vendors can leave ownership unclear.
Why it matters
Clear access and recovery notes reduce disruption when people or providers change.
Start with domain, DNS, email, MFA, and handoff checks before any redesign or cleanup work.
View cleanup sprintCommon risk
Clients may ask for questionnaire answers before the security evidence is organized.
Why it matters
Unsupported answers can create follow-up work and credibility problems later.
Use the Snapshot to establish the facts, then use Client/Vendor Security Questionnaire Support for answer drafting and gaps.
View questionnaire supportFurther reading
Start with CyberBit guidance when it matches your business decision, then compare broader guidance from government and standards organizations.
Glossary
Use these definitions when a provider, insurer, vendor, or questionnaire uses technical language.
The settings that tell the internet where your website, email, and other domain services live.
The company where your domain is registered and renewed. Registrar access should use MFA.
An email record that lists which services are allowed to send mail for your domain.
An email signature method that helps prove a message was authorized by your sending service.
A policy that tells mail receivers what to do when SPF or DKIM checks fail for your domain.
The secure website connection browsers expect before users submit forms or trust a site.
The encryption technology behind HTTPS. Owners usually see this as the website certificate.
Browser instructions that reduce common web risks such as framing, sniffing, or unsafe loading.
Multi-factor authentication. It adds a second proof beyond a password for important accounts.
Login or administrator areas that are reachable publicly and need intentional protection.
A client or partner form asking what security controls your business has in place.
A safe review of what can be checked from outside, without passwords, exploit testing, or private access.
FAQ
No. The Cybersecurity Center, free public check, and Website, Email & Domain Security Snapshot focus on safe public-signal review, business context, and practical remediation guidance. Authorized testing of a customer-controlled custom application is a separate specialized service with written scope and Rules of Engagement.
Start with HTTPS, HTTP-to-HTTPS redirects, basic security headers, SPF, DMARC, domain registrar ownership, DNS ownership, admin MFA, old vendor access, and whether you can explain who controls website, email, and DNS changes.
Do not submit passwords, recovery codes, API keys, private keys, payment details, customer records, medical records, legal files, or private screenshots through public forms. CyberBit can start with public signals and non-sensitive business context.
DMARC is an email-domain policy that helps receiving mail systems decide what to do when a message claiming to be from your domain fails SPF or DKIM checks. It should be reviewed carefully before moving from monitoring to stricter enforcement.
Security headers are browser instructions sent by a website. They can help reduce risks such as clickjacking, unsafe content loading, MIME sniffing, and overly broad browser permissions.
Vendor questionnaires often ask for evidence around MFA, backups, access control, policies, vendors, and email security. Support helps organize accurate answers and identify gaps without promising vendor approval.
Use the free public check when you want quick public signals. Use the $199 Website, Email & Domain Security Snapshot when you want CyberBit to review the 11 areas, explain business impact, prioritize findings, and give vendor-ready next steps.
If the issue is clear, compare Focused Security Cleanup or Business Security Remediation Sprint instead of buying a diagnostic first. If you still need a fix order or plain-English report, start with the Snapshot.
It can help you understand common control questions and organize vendor-ready notes, but it does not guarantee insurance approval, lower premiums, compliance status, or acceptance by an insurer.
You can share the report with your website, DNS, email, IT, or software provider. If you want CyberBit to help implement fixes, the next step may be Focused Security Cleanup, Business Security Remediation Sprint, External Security Watch, or Client/Vendor Security Questionnaire Support.
Prioritize the work
The Website, Email & Domain Security Snapshot gives you a plain-English report with public-facing findings, severity, business impact, recommended fixes, and next steps for cleanup, redesign, workspace setup, External Security Watch, questionnaire support, or vendor handoff.
CyberBit Solutions LLC provides practical website, email, domain, cloud-account, and cybersecurity foundation guidance for small businesses. This page is general guidance, not penetration testing, breach detection, compliance certification, legal advice, incident response, or a guarantee of security.