B-
82/100
No critical issues — great work!
1
Strengthen email authentication configuration
Email authentication is partially configured for gov.sg but has gaps. Actions needed: add SPF record; configure DKIM. Until DMARC enforcement is active, spoofed emails may still reach recipients.
NIST CSFPR.AC-7
Email authentication is a required access control
How to fix this
1Add SPF record if missing: v=spf1 include:_spf.google.com -all
2Configure DKIM and publish public key in DNS
3Verify with: nslookup -type=txt _dmarc.gov.sg
1 item locked
Unlock the full action plan
Sign in to see all 1 remaining recommendation.
Report unlocked.
At a glance
Full data from this scan
TLS Version
TLSv1.2
TLSv1.2 negotiated. Issues: TLS 1.2 negotiated (1.3 preferred).
DMARC Policy
p=reject
Strengths: DMARC policy set to reject (strongest). Issues: No SPF record found; No DKIM records found for common selectors (may use non-standard selectors).
SPF Record
Missing
No SPF record found.
Security Headers
4/5 present
Missing: Permissions-Policy
HSTS
Enabled
HSTS enabled: max-age=31536000. Missing includeSubDomains. Missing preload directive.
SSL Certificate
Valid
Strengths: Certificate valid, 250 days remaining; Issued by GlobalSign nv-sa.
DNSSEC
Enabled
Strengths: 4 nameservers configured (dsany2.sgnic.sg., pch.sgzones.sg., dsany3.sgnic.sg., dsany4.sgnic.sg.); DNSSEC enabled; Zone transfers properly restricted.
Similar companies
Other domains with comparable security profiles.