Start with how scanning works, or look up a finding from your report. Each check explains the evidence, its limits, and what to do next.
Getting started
- Your first SSLBoard scan
Discover public hosts, inspect their security, and find the parts of your domain that need attention.
- How SSLBoard gets its data
Understand the difference between public certificate records, DNS information, and live observations of your servers.
- Discovery and scan coverage
Learn why a hostname may be missing, why an old name still appears, and what an external scan cannot see.
Understanding results
- Reading your report
Use severity, affected hosts, endpoint evidence, and scan time together to decide what to fix.
- Missing, failed, and inconclusive results
Distinguish a confirmed configuration problem from a check that could not produce usable evidence.
- How the TLS score works
Understand category weights, affected counts, coverage gaps, and the limits of a score from 0 to 100.
Checks
- Certificate expiry, revocation, and deployment
Find certificates that need replacement and understand why a valid date alone does not establish a healthy deployment.
- CAA certificate issuance policies
Read the permitted issuer lists without confusing an empty wildcard list with a ban on wildcard certificates.
- TLS versions and deprecated protocols
Understand supported protocol versions, missing TLS 1.3, and differences between addresses serving the same hostname.
- OCSP stapling results
Understand Full, Partial, None, Not Available, Expired, Unknown, Bogus, and Revoked certificate-status responses.
- Weak and legacy cipher suites
Understand the cipher families SSLBoard flags and separate confirmed support from claims about exploitability.
- Forward secrecy
Read the difference between TLS 1.3 support, older-client coverage, and hosts with no observed forward secrecy.
- Certificate keys and algorithm choices
Interpret Recommended, Legacy, Too Small, Unknown, and RSA-only results without conflating certificate keys with key exchange.
- HTTP to HTTPS redirects
Understand why a working HTTPS site can still have an HTTP redirect finding.
- HSTS and HTTPS browser policy
Understand missing HSTS, max-age, subdomain coverage, and why preload needs a separate decision.
- Browser security headers and cookies
Read CSP, frame protection, nosniff, cookie flags, and other response-header findings in their application context.
- Connection and certificate errors
Understand DNS failures, private addresses, timeouts, TLS failures, and certificate-validation problems.
- Post-quantum TLS readiness
Understand observed hybrid key exchange, readiness gaps, and what the result does not say about the rest of your system.
- DNSSEC validation and zone findings
Distinguish unsigned DNS from broken validation, expiring signatures, weak signing profiles, and zone enumeration.
- Mail routing and TLS transport
Understand MX routing, delivery versus submission ports, STARTTLS, certificate failures, and partial email probes.
- SPF, DMARC, MTA-STS, TLS-RPT, and DANE
Read published email policies and distinguish record presence from enforcement and successful message authentication.
- Adjacent domains and certificate relationships
Understand why another domain appears in your report without assuming shared ownership or a separate security assessment.
Using reports
- Report access, sharing, and exports
Choose between the free summary and full evidence, and share the right report with the people doing the work.
- Fixing findings and verifying changes
Turn a report into assigned work, then verify the actual endpoint after deployment.