Browser security and email authentication

Security & Email: protecting visitors and your name

This covers two kinds of trust. In the browser, HTTPS and security headers protect the people visiting your site. In the inbox, SPF, DKIM and DMARC prove that email from your domain really comes from you.

What it is

Security headers are short instructions your server sends with every page. They tell browsers to only use HTTPS, which scripts may run, and whether other sites may show your page in a frame. They cost nothing to add and shut down whole classes of attack.

Email authentication is a set of DNS records. SPF lists the servers allowed to send mail as your domain, DKIM signs your messages so they can't be altered, and DMARC tells receivers what to do with mail that fails both, and where to send reports.

Why it matters

Visitors notice when a site isn't secure

Browsers label pages without HTTPS as not secure, and many people leave when they see it. HSTS goes further and tells browsers never to load your site over plain HTTP, even from an old link.

Headers stop common attacks

A Content-Security-Policy limits which scripts can run, so code injected into a page is far less likely to execute. Frame protection stops other sites loading yours in a hidden frame to trick people into clicking. nosniff stops browsers treating files as a type they're not.

Without DMARC, anyone can send mail as you

Email was designed without proof of sender. Without SPF, DKIM and an enforcing DMARC policy, a scammer can send mail that appears to come from your domain, and your customers are the ones who get phished.

Your own mail gets delivered

Gmail and Yahoo now require senders to authenticate their mail, and require SPF, DKIM and DMARC from anyone sending in bulk. Unauthenticated mail is more likely to land in spam or be rejected.

What Crawlable checks

HTTPS and HSTS
Whether the page is served over HTTPS, and whether Strict-Transport-Security is set for at least six months.
Content-Security-Policy
Whether a CSP is set that actually restricts scripts, with a default-src or script-src directive.
X-Content-Type-Options
Whether it's set to nosniff.
Frame protection
Whether X-Frame-Options or a CSP frame-ancestors directive stops other sites framing your pages.
Referrer-Policy
Whether a policy leaks full URLs to other sites. Leaving it unset is fine: browsers default to a safe policy.
SPF
Whether your domain has exactly one SPF record, and whether it stays within the 10 DNS lookups SPF allows.
DKIM
Whether we can find DKIM keys at your mail provider's selectors or common ones. There's no way to list a domain's selectors, so a miss doesn't prove DKIM is off.
DMARC
Whether you have a DMARC record, and whether its policy is quarantine or reject, which acts on fakes, or none, which only monitors.

Common problems and how to fix them

No HSTS header

Once your whole site works over HTTPS, send Strict-Transport-Security: max-age=31536000; includeSubDomains.

No Content-Security-Policy

Start in report-only mode so nothing breaks: Content-Security-Policy-Report-Only: default-src 'self'; frame-ancestors 'self'. Add the outside services your pages use, check the browser console for violations, then switch to the enforcing Content-Security-Policy header.

No DMARC record

Add a TXT record that monitors first:
_dmarc.example.com  TXT  "v=DMARC1; p=none; rua=mailto:[email protected]"
Read the reports for a few weeks. Once your own mail passes SPF or DKIM, change p=none to p=quarantine.

Two SPF records, or too many lookups

Merge everything into one record that starts v=spf1, include only services that still send mail as you, and keep it to 10 DNS lookups or fewer. Past that, receivers treat SPF as broken.

Questions

Does this score affect my search rankings?

Mostly not. HTTPS is a lightweight Google ranking signal, but the other headers and the email records don't affect how search engines or AI tools rank you. They protect your visitors and your reputation.

Will adding a Content-Security-Policy break my site?

It can, if it blocks a script or service your pages need. That's why it's best to start with Content-Security-Policy-Report-Only, which reports problems without blocking anything.

I don't send email from my domain. Do I need SPF and DMARC?

Yes, arguably more so. A domain that sends no mail can publish v=spf1 -all and a DMARC policy of p=reject, which tells receivers to refuse anything claiming to come from it.

See how your site does

Free, no email, and about a minute from typing your domain to reading the report.

Run your audit