Skip to content

Published methodology

How the Security Snapshot evaluates public signals

The Snapshot measures defined public-facing signals, not the organization's complete cybersecurity posture.

Methodology version 2026.07Reviewed 2026-07-21

The defined scope

The 11 checks in every Snapshot

Each check uses public website, DNS, or email-domain evidence. CyberBit records the observation, manually reviews the context, and explains what deserves attention.

  1. 1

    HTTPS reachability

    Website connection

    The public website responded over HTTPS during the review.

    Evidence source
    Safe request to the submitted public website host
    Limit
    Reachability does not prove that every page, form, certificate path, or private system is secure.
  2. 2

    HTTP to HTTPS redirect

    Website connection

    The public HTTP endpoint directed the request toward HTTPS.

    Evidence source
    Safe request to the public HTTP endpoint
    Limit
    A redirect does not prove that every legacy hostname or application path enforces HTTPS.
  3. 3

    HSTS

    Browser protections

    The reviewed response advertised an HSTS policy to compatible browsers.

    Evidence source
    Strict-Transport-Security response header
    Limit
    Header presence does not prove that the policy duration, subdomain coverage, or preload choice is appropriate.
  4. 4

    CSP

    Browser protections

    The reviewed response returned a Content Security Policy.

    Evidence source
    Content-Security-Policy response header
    Limit
    Presence does not prove that the policy is effective, complete, or free of unsafe exceptions.
  5. 5

    Clickjacking protection

    Browser protections

    The reviewed response included a public signal intended to restrict framing.

    Evidence source
    X-Frame-Options or relevant CSP framing directive
    Limit
    Presence does not prove that every route or embedded application has the intended framing behavior.
  6. 6

    MIME sniffing protection

    Browser protections

    The reviewed response asked compatible browsers not to MIME-sniff content.

    Evidence source
    X-Content-Type-Options response header
    Limit
    This header is one browser protection and does not validate uploaded files or application content handling.
  7. 7

    Referrer Policy

    Browser protections

    The reviewed response declared a referrer-information policy.

    Evidence source
    Referrer-Policy response header
    Limit
    Presence does not prove that the chosen policy matches every privacy or application requirement.
  8. 8

    Permissions Policy

    Browser protections

    The reviewed response declared browser-feature permissions.

    Evidence source
    Permissions-Policy response header
    Limit
    Presence does not prove that every feature is restricted appropriately for the application.
  9. 9

    MX records

    Email routing

    Public mail-routing records were observed for the submitted domain.

    Evidence source
    Public DNS MX lookup
    Limit
    MX presence does not prove inbox availability, provider ownership, deliverability, or secure account configuration.
  10. 10

    SPF

    Email authentication

    An SPF policy was observed for the submitted domain.

    Evidence source
    Public DNS TXT lookup for an SPF policy
    Limit
    Presence does not prove that every legitimate sender is included or that SPF aligns for DMARC.
  11. 11

    DMARC

    Email authentication

    A DMARC policy was observed for the submitted domain.

    Evidence source
    Public DNS TXT lookup at the domain's _dmarc hostname
    Limit
    Presence does not prove enforcement, identifier alignment, report review, or complete sender coverage.

Result language

Statuses describe evidence, not a security grade

CyberBit does not convert the checks into an overall pass/fail score. The report uses scoped statuses so an unavailable result cannot be mistaken for a passing control.

Observed
The defined public signal was present at the recorded review time. Presence does not prove effectiveness.
Attention
The defined signal was missing, weak, or otherwise needs owner or provider follow-up.
Manual review
CyberBit needs business context or provider evidence before making a supportable determination.
Unavailable
The check could not produce reliable evidence. It is not counted as observed or passed.
Not applicable
The check does not apply to the reviewed setup, with the reason documented.

Freshness

Public signals can change after a report is prepared. Each report records the observation time and methodology version so the evidence has a clear reference point.

False positives and rechecks

Proxies, redirects, DNS timing, and provider-specific behavior can affect observations. CyberBit manually reviews findings and can recheck relevant public signals when supplied context changes them.

Corrections

If a provider or owner has evidence that changes a finding, reply to the report or email CyberBit support. Corrections are evaluated against the same scoped method.

Scope boundaries

What this method cannot determine

  • No penetration testing, exploit attempts, credential testing, malware scanning, or private-system access.
  • No breach determination, forensic investigation, compliance certification, vendor approval, or insurance approval.
  • Public-signal presence does not prove that a control is effective, complete, correctly owned, or consistently deployed.
  • Results are point-in-time observations and can change after DNS, hosting, email, or website configuration changes.

Use the method on your domain

Get the $199 Security Snapshot

Receive manually verified findings, a prioritized fix order, and provider-ready instructions.