C
75/100
No critical issues — great work!
1
Strengthen email authentication configuration
Email authentication is partially configured for notion.so but has gaps. Actions needed: add SPF record; configure DKIM. Until DMARC enforcement is active, spoofed emails may still reach recipients.
NIST CSFPR.AC-7
Email authentication is a required access control
How to fix this
1Add SPF record if missing: v=spf1 include:_spf.google.com -all
2Configure DKIM and publish public key in DNS
3Verify with: nslookup -type=txt _dmarc.notion.so
3 items locked
Unlock the full action plan
Sign in to see all 3 remaining recommendations.
Report unlocked.
At a glance
Full data from this scan
TLS Version
TLSv1.3
TLSv1.3 negotiated with TLS_AES_256_GCM_SHA384 (256-bit). Strong configuration with no deprecated protocols or weak ciphers detected.
DMARC Policy
p=quarantine
Strengths: DMARC policy set to quarantine. Issues: No SPF record found; No DKIM records found for common selectors (may use non-standard selectors).
SPF Record
Missing
No SPF record found.
Security Headers
2/5 present
Missing: X-Content-Type-Options, X-Frame-Options, Permissions-Policy
HSTS
Enabled
HSTS enabled: max-age=31536000 with includeSubDomains and preload. Meets best-practice configuration.
SSL Certificate
Issues
Strengths: Certificate valid, 33 days remaining; Issued by Google Trust Services. Issues: Wildcard certificate in use — broader attack surface if compromised.
DNSSEC
Not enabled
Strengths: 2 nameservers configured (dana.ns.cloudflare.com., woz.ns.cloudflare.com.); Zone transfers properly restricted. Issues: DNSSEC not configured — DNS responses can be spoofed.
Similar companies
Other domains with comparable security profiles.