What is a domain scan?
In a domain scan you enter a web address (e.g. example.com). ZeroFlaw then checks your website from the outside – just like an attacker would. Checks include:
- SSL/TLS certificates – Is encryption configured correctly?
- HTTP security headers – Are important protections active?
- DNS configuration – Are DNS records securely configured?
- Known vulnerabilities – Is the server running outdated software?
- Open ports – Are unnecessary services exposed?
How to start a domain scan
- In the dashboard click "New scan".
- Select the "Domain scan" tab.
- Enter the domain, e.g.
my-site.com. - Click "Start scan".
Domain verification
To prevent scanning other people's websites, you must prove that the domain belongs to you:
- ZeroFlaw shows you a TXT record.
- Add this record at your domain provider (e.g. Cloudflare, GoDaddy, Namecheap) in the DNS settings.
- Wait a few minutes for the record to propagate.
- Click "Verify".
Tip
You only need to verify each domain once. After that you can run as many scans as you like.
What exactly is checked?
| Check | What is tested? |
|---|---|
| SSL/TLS | Certificate validity, expiration, encryption strength, protocol versions |
| HTTP headers | Content-Security-Policy, X-Frame-Options, Strict-Transport-Security etc. |
| DNS | SPF, DKIM, DMARC (email security), DNSSEC, CAA |
| Server | Outdated software, known CVEs, open ports |
| Cookies | Secure flag, HttpOnly, SameSite attribute |
FAQ
Can I scan subdomains?
Yes, simply enter the subdomain, e.g. shop.my-site.com. Verifying the main domain also covers subdomains.
How often should I run a domain scan?
We recommend at least once a month or after any change to your server configuration. With scheduled scans you can automate this.
My scan shows SSL errors – what should I do?
Check that your SSL certificate is still valid and issued for the correct domain. Most hosting providers offer free Let's Encrypt certificates.