DMARC is set to monitor-only (p=none)
infoThe DMARC record on flipping-cards.com uses p=none, which only reports spoofing — it doesn't stop it. Forged mail claiming to be from your domain is still delivered.
Grade A — 3 minor.
passive scan · the deep checks need you signed in · scanned 19h ago
This is a passive website security report for dev.flipping-cards.com, graded A (94/100). We checked its SSL certificate, HTTP security headers, DNS records, email spoofing protection and publicly exposed files — the same surface a browser and a search engine already see.
We found 3 issues on this scan — each has a plain-English explanation and a copy-paste fix below.
Not your site?
The DMARC record on flipping-cards.com uses p=none, which only reports spoofing — it doesn't stop it. Forged mail claiming to be from your domain is still delivered.
flipping-cards.com is not protected by DNSSEC. DNSSEC signs your DNS records so resolvers can detect a forged answer — without it, an attacker who can poison DNS could point your domain at their own server without touching anything you control.
flipping-cards.com publishes no CAA records. CAA tells the world which certificate authorities are allowed to issue HTTPS certificates for your domain. Without it, any CA can be persuaded to issue a cert for your domain, which widens the door to mis-issuance.
Sign up to fix these — then run the checks a passive scan can't. The stuff that actually gets vibe-coded apps hacked:
free for your first app · no card
Not dev.flipping-cards.com? Scan your own site free →