NodeLink / Posture Scanner
Scan results

cloudfare.com

5/2/2026, 8:12:22 PM
Download PDF
82/ 100
Risk score
Good

Issues to address (2)

HTTPS reachability

web
High

Could not fetch the site over HTTPS to inspect security headers.

Fix: Ensure the site is served over HTTPS and reachable from the public internet.

CAA records

dns
Low

No CAA records published. CAA records restrict which Certificate Authorities can issue certificates for your domain, reducing the risk of mis-issuance.

Fix: Publish CAA records naming the CAs you use, e.g. "0 issue \"letsencrypt.org\"" and "0 issue \"digicert.com\"".

Passed checks (8)

Port scan summary

ports
Info

Checked 12 common ports on 104.21.77.216. Open: 80/HTTP, 443/HTTPS.

SPF record

email
Pass

SPF record is present and uses an enforcing policy.

DMARC policy

email
Pass

DMARC is published with a strict reject policy.

DKIM detection

email
Pass

DKIM key detected at selector(s): s1, google, k1, selector1, s2, mail, selector2, default.

MX records

email
Pass

MX records present (4). Mail will be routed to mailstream-canary.mxrecord.io.

Nameserver redundancy

dns
Pass

2 nameservers configured.

TLS certificate

tls
Pass

Valid certificate issued by WE1, expires in 33 days. Protocol: TLSv1.3.

HTTP → HTTPS redirect

web
Pass

HTTP requests redirect to HTTPS.