What it is
Security headers are short instructions your server sends with every page. They tell browsers to only use HTTPS, which scripts may run, and whether other sites may show your page in a frame. They cost nothing to add and shut down whole classes of attack.
Email authentication is a set of DNS records. SPF lists the servers allowed to send mail as your domain, DKIM signs your messages so they can't be altered, and DMARC tells receivers what to do with mail that fails both, and where to send reports.
Why it matters
Visitors notice when a site isn't secure
Browsers label pages without HTTPS as not secure, and many people leave when they see it. HSTS goes further and tells browsers never to load your site over plain HTTP, even from an old link.
Headers stop common attacks
A Content-Security-Policy limits which scripts can run, so code injected into a page is far less likely to execute. Frame protection stops other sites loading yours in a hidden frame to trick people into clicking. nosniff stops browsers treating files as a type they're not.
Without DMARC, anyone can send mail as you
Email was designed without proof of sender. Without SPF, DKIM and an enforcing DMARC policy, a scammer can send mail that appears to come from your domain, and your customers are the ones who get phished.
Your own mail gets delivered
Gmail and Yahoo now require senders to authenticate their mail, and require SPF, DKIM and DMARC from anyone sending in bulk. Unauthenticated mail is more likely to land in spam or be rejected.
What Crawlable checks
- HTTPS and HSTS
- Whether the page is served over HTTPS, and whether
Strict-Transport-Securityis set for at least six months. - Content-Security-Policy
- Whether a CSP is set that actually restricts scripts, with a
default-srcorscript-srcdirective. - X-Content-Type-Options
- Whether it's set to
nosniff. - Frame protection
- Whether
X-Frame-Optionsor a CSPframe-ancestorsdirective stops other sites framing your pages. - Referrer-Policy
- Whether a policy leaks full URLs to other sites. Leaving it unset is fine: browsers default to a safe policy.
- SPF
- Whether your domain has exactly one SPF record, and whether it stays within the 10 DNS lookups SPF allows.
- DKIM
- Whether we can find DKIM keys at your mail provider's selectors or common ones. There's no way to list a domain's selectors, so a miss doesn't prove DKIM is off.
- DMARC
- Whether you have a DMARC record, and whether its policy is
quarantineorreject, which acts on fakes, ornone, which only monitors.
Common problems and how to fix them
No HSTS header
Strict-Transport-Security: max-age=31536000; includeSubDomains.No Content-Security-Policy
Content-Security-Policy-Report-Only: default-src 'self'; frame-ancestors 'self'. Add the outside services your pages use, check the browser console for violations, then switch to the enforcing Content-Security-Policy header.No DMARC record
_dmarc.example.com TXT "v=DMARC1; p=none; rua=mailto:[email protected]"
Read the reports for a few weeks. Once your own mail passes SPF or DKIM, change p=none to p=quarantine.Two SPF records, or too many lookups
v=spf1, include only services that still send mail as you, and keep it to 10 DNS lookups or fewer. Past that, receivers treat SPF as broken.Questions
Does this score affect my search rankings?
Mostly not. HTTPS is a lightweight Google ranking signal, but the other headers and the email records don't affect how search engines or AI tools rank you. They protect your visitors and your reputation.
Will adding a Content-Security-Policy break my site?
It can, if it blocks a script or service your pages need. That's why it's best to start with Content-Security-Policy-Report-Only, which reports problems without blocking anything.
I don't send email from my domain. Do I need SPF and DMARC?
Yes, arguably more so. A domain that sends no mail can publish v=spf1 -all and a DMARC policy of p=reject, which tells receivers to refuse anything claiming to come from it.