SurfaceWatch

BLOG

Website security, in plain English

Guides on the things that actually lower your security grade — headers, HTTPS, cookies, email spoofing and exposed subdomains — and the exact fixes.

COMPARISON·October 2026·5 min read

SurfaceWatch vs Security Headers: an honest comparison

Both are free and grade your site in the browser — but they're built for different jobs. Where each one wins.

Read article →
COMPARISON·October 2026·5 min read

SurfaceWatch vs Mozilla Observatory: an honest comparison

A hosted header & TLS scanner vs a whole-surface browser check — where each one wins.

Read article →
COMPARISON·October 2026·6 min read

Looking for a "Security Headers" extension alternative? Check your whole site, not just headers

Header checkers grade one slice of your exposure. Here's the full picture — and how to grade all of it in one click.

Read article →
CHECKLIST·October 2026·7 min read

How do I check if my website is secure?

A practical, 2-minute checklist — HTTPS, headers, cookies, SPF/DMARC, old JS and subdomains — with how to check each.

Read article →
ATTACK SURFACE·October 2026·6 min read

How to find exposed subdomains (and why they matter)

Admin, dev and staging subdomains are what attackers find first. How to find yours before they do.

Read article →
EMAIL SECURITY·October 2026·7 min read

SPF, DKIM and DMARC explained — and how to check your domain

The three DNS records that stop people spoofing email from your domain, in plain English.

Read article →
HOW-TO·October 2026·7 min read

The 5 security headers your site is probably missing (and the exact fixes)

The highest-leverage, lowest-effort wins in web security — with copy-paste config for nginx, Apache, Express, Vercel and Netlify.

Read article →

More guides on the way. Want one on a specific topic? Get in touch.