Step 1
Confirm scope and authorization
Record who owns or manages each website, what public checks are permitted, and who can approve changes. Do not collect customer credentials for a public baseline.
Agency field guide
A useful baseline connects an authorized asset to an observation, a finding, a decision, a fix task, and a later verification event. It keeps technical evidence clear without overstating coverage.
Baseline workflow
Step 1
Record who owns or manages each website, what public checks are permitted, and who can approve changes. Do not collect customer credentials for a public baseline.
Step 2
Record DNS email controls, TLS and HTTPS behavior, response headers, and the public homepage evidence that was actually read.
Step 3
Use confidence to describe evidence quality. A scanner status without auditable raw evidence should not be presented as a fully confirmed conclusion.
Step 4
Select the issues with the clearest business impact and evidence. Name the responsible owner and provide a precise, reviewable fix task.
Step 5
The authorized developer, DNS administrator, email provider, or host reviews and applies the change. External monitoring should not modify production automatically.
Step 6
Collect a later independent observation. Mark a fix verified only when comparable before-and-after evidence supports that conclusion.
Responsible boundary
Public observations are valuable when their scope stays explicit. Unread pages, authenticated systems, application code, and internal infrastructure remain outside this first-pass evidence.
The sample report shows how public evidence, confidence, business impact, responsible ownership, and before-and-after verification fit together. Sample findings remain clearly labeled as sample data.