CBWATCH
← CBWatch

Security guides

Plain-English explanations of exactly what each CBWatch check looks at, why it matters, and how to fix what it flags — one guide per check.

What are SPF, DMARC, and DKIM?

Three DNS records that determine whether someone else can send email that looks like it came from your domain.

What does a TLS/SSL certificate check look at?

Certificate validity and expiry, obsolete protocol support, and whether HTTP redirects to HTTPS — and why each matters.

What are HTTP security headers?

What headers like HSTS, Content-Security-Policy, and X-Frame-Options actually do, and what a site risks without them.

How to check if your domain's been in a data breach

How breach exposure checks work — checking common role addresses like info@ and admin@ against known breaches.

What do open ports and exposed services reveal?

What an open-ports check on your server's public IP actually shows, and the limits of this kind of scan.

Is your WordPress site behind on security updates?

Why running an outdated WordPress version matters, and how to check if your site is behind a major release.

Why an exposed .git folder or .env file is a critical risk

How files like .git/, .env, and database backups end up publicly downloadable, and why it's one of the most damaging mistakes a site can make.

Why domain expiry is a bigger risk than most people realise

What happens when a domain registration lapses, why it's worse than a certificate expiring, and how to make sure it never happens by accident.

What is security.txt, and why does it matter?

A standardised file that tells security researchers exactly how to report a vulnerability — and how CBWatch can generate one for you.

Every check here reads publicly available information only — nothing logs in, guesses passwords, or probes for vulnerabilities. See the full methodology for how scoring works end to end.