ZeroFlaw

Documentation

Domain scan

What is a domain scan?

In a domain scan you enter a web address (e.g. example.com). ZeroFlaw then checks your website from the outside – just like an attacker would. Checks include:

  • SSL/TLS certificates – Is encryption configured correctly?
  • HTTP security headers – Are important protections active?
  • DNS configuration – Are DNS records securely configured?
  • Known vulnerabilities – Is the server running outdated software?
  • Open ports – Are unnecessary services exposed?

How to start a domain scan

  1. In the dashboard click "New scan".
  2. Select the "Domain scan" tab.
  3. Enter the domain, e.g. my-site.com.
  4. Click "Start scan".

Domain verification

To prevent scanning other people's websites, you must prove that the domain belongs to you:

  1. ZeroFlaw shows you a TXT record.
  2. Add this record at your domain provider (e.g. Cloudflare, GoDaddy, Namecheap) in the DNS settings.
  3. Wait a few minutes for the record to propagate.
  4. Click "Verify".
Tip You only need to verify each domain once. After that you can run as many scans as you like.

What exactly is checked?

CheckWhat is tested?
SSL/TLSCertificate validity, expiration, encryption strength, protocol versions
HTTP headersContent-Security-Policy, X-Frame-Options, Strict-Transport-Security etc.
DNSSPF, DKIM, DMARC (email security), DNSSEC, CAA
ServerOutdated software, known CVEs, open ports
CookiesSecure flag, HttpOnly, SameSite attribute

FAQ

Can I scan subdomains?

Yes, simply enter the subdomain, e.g. shop.my-site.com. Verifying the main domain also covers subdomains.

How often should I run a domain scan?

We recommend at least once a month or after any change to your server configuration. With scheduled scans you can automate this.

My scan shows SSL errors – what should I do?

Check that your SSL certificate is still valid and issued for the correct domain. Most hosting providers offer free Let's Encrypt certificates.