BLOG
Website security, in plain English
Guides on the things that actually lower your security grade — headers, HTTPS, cookies, email spoofing and exposed subdomains — and the exact fixes.
SurfaceWatch vs Security Headers: an honest comparison
Both are free and grade your site in the browser — but they're built for different jobs. Where each one wins.
Read article →SurfaceWatch vs Mozilla Observatory: an honest comparison
A hosted header & TLS scanner vs a whole-surface browser check — where each one wins.
Read article →Looking for a "Security Headers" extension alternative? Check your whole site, not just headers
Header checkers grade one slice of your exposure. Here's the full picture — and how to grade all of it in one click.
Read article →How do I check if my website is secure?
A practical, 2-minute checklist — HTTPS, headers, cookies, SPF/DMARC, old JS and subdomains — with how to check each.
Read article →How to find exposed subdomains (and why they matter)
Admin, dev and staging subdomains are what attackers find first. How to find yours before they do.
Read article →SPF, DKIM and DMARC explained — and how to check your domain
The three DNS records that stop people spoofing email from your domain, in plain English.
Read article →The 5 security headers your site is probably missing (and the exact fixes)
The highest-leverage, lowest-effort wins in web security — with copy-paste config for nginx, Apache, Express, Vercel and Netlify.
Read article →More guides on the way. Want one on a specific topic? Get in touch.