Client summary
Restaurante Demo needs website trust and email protection fixes.
- Customer
- Restaurante Demo
- Domain
- restaurante-demo.com
- Report type
- Public demo data
- Next action
- Send fix notes to technician
Sample report
This public sample uses static mock data only. It shows how a small business owner can understand the risk and how a technician can receive clear fix instructions.
Change the language to preview the existing report translation layer.
Client summary
Score
45/100
Current website exposure score.
Risk level
Medium Risk
Several configuration items should be fixed before relying on the website and email domain for customer trust.
Executive summary
The site has a few configuration gaps that can affect trust, email delivery, or browser protection. These are usually fixable by the website host, developer, or email provider.
Business impact
Evidence confidence
Every scanner result is separated into evidence confidence, public exposure, action priority, and verification status. Confidence describes evidence quality, not vulnerability severity.
Confirmed issues
2
Need validation
3
Publicly observable
5
Fixed and verified
0
Findings
Each finding shows the business impact, likely responsible owner, fix effort, steps, and the exact message to copy.
Needs attention
This checks whether visitors who type the old non-secure address are automatically moved to the secure website.
Why this priority
Priority score: 60/100. This is a workflow score, not a CVSS rating.
Stored evidence
The public scan observation returned Missing.
Business impact
Without this redirect, some customers may land on a less trusted version of the site.
Responsible owner
Website host or web developer
Fix difficulty
Easy to medium | 15 minutes to 1 hour
Fix steps
Technician message preview
Domain: restaurante-demo.com Check: Automatic HTTPS redirect Observed status: Missing Configure a 301 redirect from HTTP to HTTPS at the CDN, host, web server, or application layer. Verify final URLs resolve to HTTPS.
Needs attention
This checks whether your domain says which services are allowed to send email for your business.
Why this priority
Priority score: 38/100. This is a workflow score, not a CVSS rating.
Stored evidence
The public scan observation returned Missing.
Business impact
Missing SPF can make real email less reliable and makes it easier for others to fake messages from your domain.
Responsible owner
Email provider or DNS administrator
Fix difficulty
Medium | 30 minutes to 2 hours
Fix steps
Technician message preview
Domain: restaurante-demo.com Check: Email sender authorization Observed status: Missing Publish one SPF TXT record at the root domain. Include all approved mail senders and avoid multiple v=spf1 records.
Needs attention
This checks whether your domain tells mail systems what to do when a message fails identity checks.
Why this priority
Priority score: 60/100. This is a workflow score, not a CVSS rating.
Stored evidence
The public scan observation returned Missing.
Business impact
Without DMARC, fake emails can be harder to control and customers may receive messages that appear to be from your business.
Responsible owner
Email provider or DNS administrator
Fix difficulty
Medium | 30 minutes to half a day
Fix steps
Technician message preview
Domain: restaurante-demo.com Check: Email impersonation policy Observed status: Missing Publish a DMARC TXT record at _dmarc.domain. Start with p=none if sender inventory is incomplete, then progress to quarantine or reject after review.
Needs attention
This checks whether browsers are told to remember that your site should use the secure version.
Why this priority
Priority score: 55/100. This is a workflow score, not a CVSS rating.
Stored evidence
strict-transport-security was not observed in the homepage response.
Business impact
Without this, repeat visitors have less protection if a network tries to downgrade their connection.
Responsible owner
Website host or web developer
Fix difficulty
Medium | 30 minutes to 2 hours
Fix steps
Technician message preview
Domain: restaurante-demo.com Check: Browser HTTPS memory Observed status: Missing Add Strict-Transport-Security after confirming HTTPS coverage. Start with a cautious max-age before considering includeSubDomains or preload.
Needs attention
This checks whether your website gives browsers rules about where scripts, images, and other content may load from.
Why this priority
Priority score: 65/100. This is a workflow score, not a CVSS rating.
Stored evidence
content-security-policy was not observed in the homepage response.
Business impact
A missing policy can make certain website mistakes more damaging, especially on sites with forms, booking tools, or customer data.
Responsible owner
Website developer
Fix difficulty
Medium to advanced | 2 hours to 1 day
Fix steps
Technician message preview
Domain: restaurante-demo.com Check: Browser content rules Observed status: Missing Implement a Content-Security-Policy header based on actual asset and script sources. Test in report-only mode if needed before enforcing.
Before
45/100
Missing email protection and browser safety headers created a practical trust and reputation risk.
After
82/100
SPF, DMARC, HTTPS redirect, and basic headers were fixed, so the follow-up report can show visible progress.
PDF report preview
Download a simple PDF generated from this mock report. Real saved reports can include your agency profile and can be used for client follow-up.
Secondary technical output
The raw labels remain available for the technician, but the client report above is the primary experience.
Confirms the website can be reached with a valid TLS certificate.
Checks whether HTTP visitors are automatically moved to HTTPS.
Looks for sender authorization that helps prevent email spoofing.
Checks whether the domain publishes a policy for failed mail authentication.
Reviews whether browsers are told to keep using HTTPS on later visits.
Checks for browser rules that limit where scripts and content can load from.
Checks whether the site limits being embedded inside another page.
Try it with your website
Public scanning remains available without login. Sign in when you want saved history, comparison, and client-ready PDFs.