What you actually receive
Below is an anonymised excerpt from a real assessment run, in the same format every report ships in. Real findings, real severity ratings - target replaced with a placeholder domain.
DNS Reconnaissance
| Type | Value |
|---|---|
| A | 104.20.23.154 |
| A | 172.66.147.243 |
| NS | elliott.ns.cloudflare.com. |
| NS | hera.ns.cloudflare.com. |
| TXT | "v=spf1 -all" |
No subdomains discovered
Port Scan Results
| Port | Service | Risk |
|---|---|---|
| 25 | SMTP | MEDIUM |
| 443 | HTTPS | MEDIUM |
| 465 | SMTPS | MEDIUM |
| 993 | IMAPS | MEDIUM |
8 ports total detected open - 4 shown above.
SSL/TLS Analysis
| Property | Value |
|---|---|
| Issuer | Cloudflare TLS Issuing ECC CA 3 |
| Valid Until | 27 Oct 2026 |
| Protocol | TLSv1.3 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Self-Signed | No |
| Severity | Finding |
|---|---|
| No SSL issues detected | |
Web Security Headers
| Missing Header | Severity | Recommendation |
|---|---|---|
| Strict-Transport-Security | HIGH | max-age=31536000; includeSubDomains; preload |
| Content-Security-Policy | HIGH | Define a strict CSP to prevent XSS and injection. |
| X-Frame-Options | MEDIUM | X-Frame-Options: DENY |
| Referrer-Policy | LOW | strict-origin-when-cross-origin |
No sensitive paths found
CVE Lookup (NVD)
No CVEs identified from detected service banners.
This is a real, anonymised excerpt - target domain and identifying values replaced with a placeholder. Your report covers every finding, not just the excerpt shown here.
Download a full sample report
Three complete PDF reports for a fictional client ("Fernbridge Analytics"), generated by the same scanner and report template every real client receives - not a mockup.
Vulnerability Assessment
Full DNS, port, SSL/TLS, header, and CVE report (PDF)
Email Security Check
SPF/DKIM/DMARC report with a real recommendation (PDF)
Domain & DNS Health Check
A clean-pass example report (PDF)
Fernbridge Analytics is a fictional company for demonstration purposes - each PDF is clearly labelled as a sample.