CyberBit Solutions
Website, Email & Domain Security Snapshot
Sample business: Harbor & Pine Dental
Domain reviewed: harborpinedental.example
Example assessment
Priority review recommended
5 of 11 checks observed
Version 2026.09 · July 15, 2026 at 10:30 AM ET
Executive summary
This sample domain shows useful public-facing security signals, but several items are worth reviewing before relying on the setup for vendor, insurance, or client-trust conversations. In this fictional example, 5 checks were observed, 3 need attention, 1 requires manual review, 1 was unavailable, and 1 was documented as not applicable. Unavailable checks are not counted as observed. The highest-value next step is to confirm who owns each setting, then address the DMARC and website-header findings.
The Snapshot measures defined public-facing signals, not the organization's complete cybersecurity posture.
11 defined checks
Each status applies only to the named public-facing check at the example assessment time. Header or DNS-record presence does not automatically prove effective configuration.
Manual-review note: DKIM is not one of the 11 public checks because it cannot always be discovered reliably without a selector or an actual message header.
HTTPS reachability
ObservedThe sample website responded over HTTPS at the assessment time.
Safe request to the submitted public website host
HTTP to HTTPS redirect
ObservedThe public HTTP endpoint redirected the sample request to HTTPS.
Safe request to the public HTTP endpoint
HSTS
ObservedAn HSTS header was returned; policy strength still needs contextual review.
Strict-Transport-Security response header
CSP
AttentionNo enforceable CSP was observed on the representative response.
Content-Security-Policy response header
Clickjacking protection
Manual reviewFraming behavior needs manual confirmation because the available policy evidence was ambiguous.
X-Frame-Options or relevant CSP framing directive
MIME sniffing protection
UnavailableThe representative response was inconsistent, so this check is not counted as observed.
X-Content-Type-Options response header
Referrer Policy
AttentionNo explicit Referrer-Policy was observed on the representative response.
Referrer-Policy response header
Permissions Policy
Not applicableThis fictional scope records the policy as not applicable, with the reason documented in the full report.
Permissions-Policy response header
MX records
ObservedPublic MX records were observed for the sample domain.
Public DNS MX lookup
SPF
ObservedAn SPF policy was observed; sender completeness and DMARC alignment still need context.
Public DNS TXT lookup for an SPF policy
DMARC
AttentionA DMARC record was observed in monitoring mode and needs provider review before enforcement.
Public DNS TXT lookup at the domain's _dmarc hostname
Top findings preview
Finding 01
DMARC policy needs enforcement review
- Observed
- A DMARC record was present in this sample, but the policy was set to monitoring mode instead of enforcement.
- Why it matters
- DMARC helps reduce fake emails that appear to come from the business domain. Monitoring is useful, but it may not stop spoofed mail by itself.
- Recommended fix
- Review SPF, DKIM, and legitimate senders first, then move toward a stronger DMARC policy with the email provider.
Finding 02
Website security headers need cleanup
- Observed
- The sample website responded over HTTPS, but several browser security headers were not returned in the public response checked.
- Why it matters
- Security headers can help reduce certain browser-based risks and make the website setup easier for a vendor or developer to review.
- Recommended fix
- Ask the website host, CDN, or developer to review HSTS, CSP, frame protection, MIME sniffing protection, Referrer-Policy, and Permissions-Policy.
Finding 03
Domain ownership and admin access should be documented
- Observed
- The sample intake indicated that domain, website, DNS, and email administration were split across multiple vendors.
- Why it matters
- When ownership is unclear, security fixes take longer and recovery is harder during a domain, email, or website incident.
- Recommended fix
- Document the domain registrar, DNS host, website host, email provider, admin contacts, and MFA status for each account.
Next step
Want this for your own business? Start the $199 Website, Email & Domain Security Snapshot.
Get 11 defined public-facing checks, manual verification, a professional report, prioritized fixes, and provider-ready next steps for your own domain.
Start $199 SnapshotPriority action plan
- 1Confirm who manages domain registration, DNS, website hosting, and business email.
- 2Review email authentication in order: SPF, DKIM, then DMARC.
- 3Ask the website host or developer to review missing website security headers.
- 4Confirm public admin or login exposure is intentional, protected, and documented.
- 5Save before-and-after evidence once public records or headers are updated.
- 6Use cleanup, secure redesign, workspace setup, External Security Watch, questionnaire support, or vendor handoff if implementation help is needed after the Snapshot.
What this review includes
The Snapshot reviews 11 defined public-facing website, email, and domain checks plus customer-provided context. It does not include logins, exploit testing, credential testing, or private-system access.
Optional next step: cleanup, secure redesign, workspace setup, External Security Watch, questionnaire support, or vendor handoff for implementation help.
Scope and limitations
- No penetration testing, exploit attempts, credential testing, malware scanning, or private-system access.
- No breach determination, forensic investigation, compliance certification, vendor approval, or insurance approval.
- Public-signal presence does not prove that a control is effective, complete, correctly owned, or consistently deployed.
- Results are point-in-time observations and can change after DNS, hosting, email, or website configuration changes.