Steps to improve boeing.com's security grade, ranked by impact.
The HSTS header is missing on boeing.com. Without it, connections can be downgraded from HTTPS to HTTP via man-in-the-middle attacks. This is a straightforward server configuration change.
boeing.com scored 82/100, demonstrating a strong security posture. Minor improvements are noted below.
Critical gaps in: HSTS Header. Positive signals: MX Records & Mail Provider, TLS Configuration, TLS Protocol Support all passed.
3 action items identified, including 0 critical. The issues are configuration gaps, not architectural problems. A focused remediation effort of 2–5 days could address all findings.
Grade distribution across 2685 companies we've scanned. boeing.com scores better than 72% of them.
Key data points from the scan.
Other domains with comparable security profiles.