Protect
Attack surface
HTTP security headers
Each discovered host graded on HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy. Hosts graded D or F are missing multiple protections. Swept on the daily cert probe.