Tell Me When Down
How it worksWhat we checkPricing
Security reportsBlogFree toolsCompareDocs
Log inGet started
← all reportsscan another site →
C

plow.co

Grade C — 3 to fix, 3 minor.

0critical3to fix3minor

passive scan · the deep checks need you signed in · scanned 22d ago

This is a passive website security report for plow.co, graded C (73/100). We checked its SSL certificate, HTTP security headers, DNS records, email spoofing protection and publicly exposed files — the same surface a browser and a search engine already see.

We found 6 issues on this scan — each has a plain-English explanation and a copy-paste fix below.

Not your site? Get the same free report for yours →

Email spoofing protection02

No SPF record

warning

The domain plow.co publishes no SPF record. SPF is the DNS record that lists which mail servers are allowed to send email as your domain. Without it, spam filters have no way to tell your real mail from a forgery, and messages you do send are more likely to land in spam.

No DMARC record — your domain can be spoofed

warning

The domain plow.co publishes no DMARC record. DMARC is what tells receiving mail servers to reject or quarantine messages that fail your SPF/DKIM checks. Without it, an attacker can send phishing emails with a "From:" address at your domain and inboxes have no signal to distrust them — a favourite trick for invoice fraud and credential phishing.

Exposed attack surface01

6 sensitive subdomains publicly discoverable

warning

Public Certificate Transparency logs reveal internal-looking hostnames under plow.co: demo.plow.co, dev.plow.co, old.plow.co, old.shop.plow.co, staging.plow.co, test.plow.co. Names like staging, dev, and admin are found by attackers the same way we found them here — from public logs, no scanning required — and these hosts are often left less protected than production.

Security headers01

No X-Content-Type-Options

info

Without `X-Content-Type-Options: nosniff`, browsers may guess ("sniff") the type of a response and, for example, run an uploaded file as JavaScript. It's a one-line header that closes a whole class of content-type confusion bugs.

DNS security02

DNSSEC is not enabled

info

plow.co is not protected by DNSSEC. DNSSEC signs your DNS records so resolvers can detect a forged answer — without it, an attacker who can poison DNS could point your domain at their own server without touching anything you control.

No CAA records

info

plow.co publishes no CAA records. CAA tells the world which certificate authorities are allowed to issue HTTPS certificates for your domain. Without it, any CA can be persuaded to issue a cert for your domain, which widens the door to mis-issuance.

Get the fixes — and go deeper

Sign up to fix these — then run the checks a passive scan can't. The stuff that actually gets vibe-coded apps hacked:

  • Exposed .env files (API keys & passwords)
  • Public .git folders (your whole codebase)
  • Leaked source maps of your original code
  • Open admin panels with no login
  • Debug pages left on (phpinfo, stack traces)
Fix these & go deeper

free for your first app · no card

Not plow.co? Scan your own site free →

Or browse every site we've graded.

Tell Me When Down

Uptime and security monitoring for people who'd rather ship than babysit servers. We watch so you can sleep.

product
How it worksWhat we checkSecurity reportsPricingDocsBlogFAQ
free toolsWebsite security scanSupabase pause checkRender sleep checkMixed content checkerSecurity headers checkCookie security checkSSL expiry check
comparevs UptimeRobotvs Better Stackvs PingdomFor indie hackers
company
StatusAbout our botContactPrivacyTerms
© 2026 TellMeWhenDown · tellmewhendown.com