What you actually receive
Below is an anonymised excerpt from a real assessment run, in the same format every report ships in. Real findings, real severity ratings - target replaced with a placeholder domain.
47
Risk Score /100
8
Open Ports
1
SSL Issues
6
Missing Headers
0
Sensitive Paths
0
Subdomains
DNS Reconnaissance
| Type | Value |
|---|---|
| A | 104.20.23.154 |
| A | 172.66.147.243 |
| NS | elliott.ns.cloudflare.com. |
| NS | hera.ns.cloudflare.com. |
| TXT | "v=spf1 -all" |
No subdomains discovered
Port Scan Results
| Port | Service | Risk |
|---|---|---|
| 25 | SMTP | MEDIUM |
| 443 | HTTPS | MEDIUM |
| 465 | SMTPS | MEDIUM |
| 993 | IMAPS | MEDIUM |
8 ports total detected open - 4 shown above.
SSL/TLS Analysis
| Property | Value |
|---|---|
| Protocol | TLSv1.3 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Self-Signed | YES |
| Severity | Finding |
|---|---|
| HIGH | Self-signed certificate - not trusted by browsers |
Web Security Headers
| Missing Header | Severity | Recommendation |
|---|---|---|
| Strict-Transport-Security | HIGH | max-age=31536000; includeSubDomains; preload |
| Content-Security-Policy | HIGH | Define a strict CSP to prevent XSS and injection. |
| X-Frame-Options | MEDIUM | X-Frame-Options: DENY |
| Referrer-Policy | LOW | strict-origin-when-cross-origin |
No sensitive paths found
CVE Lookup (NVD)
No CVEs identified from detected service banners.
This is a real, anonymised excerpt - target domain and identifying values replaced with a placeholder. Your report covers every finding, not just the excerpt shown here.