"Is my website secure?" is a big question, but a lot of it comes down to a short list of things that are publicly visible — the surface an attacker looks at first. You can check most of it in a couple of minutes. Here's the checklist, with how to check each item by hand, and how to do it all at once.
1. HTTPS — and that it's enforced
Not just "is there a padlock," but: does http:// redirect to https://, and is HSTS set so browsers refuse to downgrade?
Check: type the http:// version and watch it redirect; run curl -sI https://yoursite.com and look for a Strict-Transport-Security header.
2. Security headers
The big ones: Content-Security-Policy (stops XSS), X-Frame-Options / frame-ancestors (stops clickjacking), X-Content-Type-Options: nosniff, and Referrer-Policy.
Check: curl -sI https://yoursite.com and read the headers, or open DevTools → Network → click the document → Response Headers.
3. Cookies
Session and login cookies should set Secure, HttpOnly and SameSite. Without HttpOnly, a single injected script can steal a session.
Check: DevTools → Application → Cookies, and look at the flag columns.
4. Email spoofing (SPF & DMARC)
If your domain's DNS is missing SPF and DMARC, anyone can send email that looks like it's from you.
Check: dig TXT yourdomain.com (look for v=spf1) and dig TXT _dmarc.yourdomain.com (look for v=DMARC1).
5. Outdated JavaScript libraries
A front-end still shipping an old jQuery or framework with known CVEs is exploitable no matter how good your headers are.
Check: look at the scripts the page loads and compare versions against known advisories.
6. Exposed subdomains
Public certificate logs reveal the subdomains you've issued certs for — and that list often includes admin., dev. or staging. systems you didn't mean to expose.
Check: search your domain on crt.sh, or see our guide on finding exposed subdomains.
The fast way: all six at once
Checking each of these by hand works, but it's tedious to repeat. This is exactly what SurfaceWatch does in one click: it grades all six layers A–F for the page you're on and gives the exact copy-paste fix for each issue — including on staging or logged-in pages a hosted scanner can't reach. It's a free Chrome extension, and the checks are passive, so it's safe to run on any site.
What this checklist does NOT cover
Be honest with yourself about scope. This is the surface — what's publicly observable. A clean grade here does not mean your site is fully secure. It says nothing about:
- Authentication and access control (can users reach things they shouldn't?)
- Injection and business-logic flaws (SQLi, IDOR, broken workflows)
- Server-side dependencies and patching
- Backups, secrets management and account security
Those need code review and, for anything serious, a real penetration test. The surface checklist is the high-value easy 20% — do it first, then go deeper.