❓ Frequently Asked Questions
Answers to the most common questions about website security checks, email protection and our services.
🔍 General questions
A website security check is a process of analyzing different aspects of a website to identify potential vulnerabilities and security flaws. It includes analysis of DNS records, SSL certificate, security headers, WAF protection, email security and much more.
Yes, the basic website check is completely free and available to everyone without registration. For detailed analysis, penetration test and professional report, contact us.
We recommend checking at least once a month, or after every major change on the site (new features, CMS updates, hosting changes). If you have an online store or handle sensitive data, checks should be more frequent.
Yes, our free check uses only publicly available data (DNS, SSL, WHOIS) and does not represent an attack on your system. For detailed analysis and penetration testing, written permission from the site owner is required.
🛡️ Security
An SSL certificate enables encryption of communication between your site and visitors. Without it, all data (passwords, card numbers) travels unprotected. Google also favors sites with HTTPS in search results.
WAF (Web Application Firewall) is a protective layer that filters malicious requests to your site. It protects against SQL injection, XSS attacks, DDoS and other threats. Popular WAFs are Cloudflare, Sucuri and AWS WAF.
Security headers are HTTP responses that tell the browser how to behave with your site. For example, HSTS forces HTTPS, X-Frame-Options protects against clickjacking, and CSP protects against XSS attacks. Their absence is a common security flaw.
A penetration test (pentest) is a simulation of an attack on your system under controlled conditions. The goal is to find vulnerabilities before attackers do. It includes testing authentication, SQL injection, XSS, CSRF and other attacks.
💰 Services & Pricing
The price of detailed analysis depends on the size and complexity of the website. For smaller sites prices start from 50 EUR, while for complex systems they can exceed 500 EUR. Contact us for an exact quote.
With the detailed analysis you get: web application penetration test, vulnerability testing (SQL injection, XSS, CSRF), authentication and API security analysis, professional PDF report with evidence, fix recommendations and post-report consultation.
For smaller sites, analysis takes 2-3 business days. For complex systems it can take 5-10 business days. Exact deadline is provided with the quote.
Yes, the guarantee is as follows: if after our analysis and fixes a security incident occurs that we missed, we will perform a re-analysis for free. Please note that the analysis service is charged regardless of the number of vulnerabilities found — you pay for time, expertise and a professional report. If we find no vulnerabilities, that is great news — your site is well protected!
📧 Email Security
Use our free email check tool. Enter your email address and you will get a list of known breaches it appears in, with details of what was leaked.
If your email is found in a breach: 1) Immediately change the password on that service, 2) Enable 2FA where possible, 3) Do not use the same password on multiple sites, 4) Use a password manager (Bitwarden, 1Password).
SPF, DKIM and DMARC are email security protocols. SPF defines which servers can send email on behalf of your domain. DKIM digitally signs emails. DMARC defines what to do with emails that fail verification. Their absence enables phishing attacks in your domain name.