What you actually receive

Below is an anonymised excerpt from a real assessment run, in the same format every report ships in. Real findings, real severity ratings - target replaced with a placeholder domain.

Fieldnote Security Report - example.com
47
Risk Score /100
8
Open Ports
1
SSL Issues
6
Missing Headers
0
Sensitive Paths
0
Subdomains

DNS Reconnaissance

TypeValue
A104.20.23.154
A172.66.147.243
NSelliott.ns.cloudflare.com.
NShera.ns.cloudflare.com.
TXT"v=spf1 -all"

No subdomains discovered

Port Scan Results

PortServiceRisk
25SMTPMEDIUM
443HTTPSMEDIUM
465SMTPSMEDIUM
993IMAPSMEDIUM

8 ports total detected open - 4 shown above.

SSL/TLS Analysis

PropertyValue
ProtocolTLSv1.3
Cipher SuiteTLS_AES_256_GCM_SHA384
Self-SignedYES
SeverityFinding
HIGHSelf-signed certificate - not trusted by browsers

Web Security Headers

Missing HeaderSeverityRecommendation
Strict-Transport-SecurityHIGHmax-age=31536000; includeSubDomains; preload
Content-Security-PolicyHIGHDefine a strict CSP to prevent XSS and injection.
X-Frame-OptionsMEDIUMX-Frame-Options: DENY
Referrer-PolicyLOWstrict-origin-when-cross-origin

No sensitive paths found

CVE Lookup (NVD)

No CVEs identified from detected service banners.

This is a real, anonymised excerpt - target domain and identifying values replaced with a placeholder. Your report covers every finding, not just the excerpt shown here.

Want to see this run against your own domain?

Request an assessment