Steps to improve websdr.org's security grade, ranked by impact.
Without email authentication, anyone can send emails that appear to come from websdr.org. This is the most common vector for phishing attacks targeting employees and customers. DMARC, DKIM are not configured.
websdr.org scored 57/100 and does not meet the minimum security posture threshold. The most critical issue is: Set up email authentication (DMARC, DKIM). This must be addressed before the vendor can be approved for procurement or data processing activities.
Critical gaps in: HSTS Header, Security Headers, DMARC / Email Security. Positive signals: MX Records & Mail Provider, TLS Configuration, DNS Configuration all passed.
4 action items identified, including 1 critical. The issues are configuration gaps, not architectural problems. A focused remediation effort of 2–5 days could address all findings.
Grade distribution across 2678 companies we've scanned. websdr.org scores better than 18% of them.
Key data points from the scan.
Other domains with comparable security profiles.