Skip to main content

Reading your report

Use severity, affected hosts, endpoint evidence, and scan time together to decide what to fix.

On this page

Start with the scan date and the domain, then read the priority findings. The overall score helps summarize the report, but the details tell you which service needs attention.

Hostnames, endpoints, and certificates

A hostname is a DNS name such as www.example.com. An endpoint identifies a network address and port in the context of the hostname being tested. A certificate can appear on several endpoints and cover several names.

These counts answer different questions. Ten affected endpoints might belong to one hostname behind a load balancer. One certificate might need replacing on several servers. Do not add counts from overlapping findings and assume the total is a count of unique services.

The report can include an AI-generated summary of the computed findings, with a standard fallback when that narrative is unavailable. This summary helps explain the report, but its underlying tables are the evidence to use when validating a claim. If a narrative and an endpoint observation appear inconsistent, preserve the specific evidence and ask for clarification rather than treating prose as another independent test.

Read a finding from evidence to action

For each finding, identify the hostname, the address and port where available, and the observed behavior. Then identify who controls that connection: your server team, CDN provider, hosting vendor, or mail provider.

For example, a hostname that supports TLS 1.3 may also support TLS 1.0. The modern version does not cancel the older support. Similarly, a healthy IPv4 endpoint does not establish that the IPv6 endpoint has the same certificate.

What severity means

Critical findings deserve prompt investigation because the report has identified a serious configuration concern. Warnings identify weaknesses or deployment gaps that need review. Informational findings supply context or improvement opportunities, such as broader algorithm support.

Severity is not a statement that an attack has occurred. Report headlines group observations, while the score breakdown applies individual scoring rules. Their labels can differ: the protocol headline groups deprecated versions together, for example, while the score treats TLS 1.1 separately from TLS 1.0.

Check the coverage behind a reassuring result

If a check has no usable observations, the absence of a finding is not proof of safety. Review connection errors and result states alongside the score. Optional sections can be absent in older reports or when no corresponding data was collected.

After choosing a finding, follow its documentation link for the interpretation and next steps. Keep the report date and affected endpoints with any ticket you send to the person making the fix.

Try these checks on your own domain: Start a free scan. If a result needs a closer look, contact us.