Sample report — This is a real ClearScan scan of google.com, run on June 22, 2026. Your report will show your own domain's data.

F · 0out of 100GoodSecurity Posture Score

Security Report

google.com

Scanned June 22, 2026 · General Business · External scan only

12

Checks run

3

Passed

6

Findings

Email Security

Partial

SPF (Sender Policy Framework)

v=spf1 include:_spf.google.com ~all

Passed

DKIM (DomainKeys Identified Mail)

Note: No DKIM selector detected at common selectors — google.com uses a custom selector not checked by automated scanners.

Partial

DMARC policy

v=DMARC1; p=reject; rua=mailto:mailauth-reports@google.com

Passed

DMARC policy is set to p=reject — the strictest level. Emails that fail authentication are rejected outright rather than quarantined. SPF record correctly scopes authorized senders.

TLS / SSL Encryption

Passed

ClearScan rating: Secure

Passed

Security Headers

Gap

Strict-Transport-Security (HSTS)

Gap

X-Content-Type-Options

Gap

X-Frame-Options

Passed

Content-Security-Policy

Partial

Referrer-Policy

Partial

google.com (root) redirects to www.google.com — HSTS and X-Content-Type-Options are present on the www subdomain. Redirect responses do not include these headers.

Website Software

Not measured

google.com is served through Google’s own front end, which hides the software running behind it — we couldn’t determine what it runs.

Not measured

This check looks only at your public website — the software your site discloses about itself, and whether that exact version has publicly documented security flaws. It does not examine network services, remote-access tools, or any device on your office network.When a site doesn't disclose a version we can trust, we look nothing up and report no result rather than guess — it stays out of the score, never counted against you.

Breach Exposure

Partial

0 breaches found for @google.com

Passed

Findings & Recommendations

Prioritized by severity — this is the list you hand to whoever manages your IT.

High

HSTS not detected on root domain

The Strict-Transport-Security header was not found on the root domain response. Visitors who type "google.com" without HTTPS may be susceptible to downgrade attacks before the redirect fires.

How to fix: Ensure HSTS is set on the root domain response, not just after redirect. Add a preload entry if possible.

High

X-Content-Type-Options header missing

Without this header, some browsers may try to sniff content types, potentially executing malicious content as a different type than intended.

How to fix: Add X-Content-Type-Options: nosniff to all server responses including redirect responses.

Medium

DKIM could not be verified

Automated DKIM scanning checks common selectors. A custom or non-standard selector could not be found. If DKIM is configured with a non-standard selector, this finding can be ignored.

How to fix: Confirm DKIM is enabled in your email provider settings and that the selector is published in DNS.

Medium

Website software version could not be determined

This site is served through a front end that hides the software running behind it, so we could not check that software against public vulnerability databases. That is not a pass and not a mark against the site — it simply could not be measured, so it is excluded from the score.

How to fix: Nothing to do. If you want the check to run, ask your host whether the origin server can report its version.

Low

TLS worth an independent second opinion

ClearScan rates this site Secure: the certificate is trusted, covers this address, and only modern TLS versions are accepted. We check the things that break a site for real visitors, not every cipher-level detail.

How to fix: Ask whoever manages the site to review your TLS settings; ssllabs.com/ssltest gives an independent second opinion.

Low

Content Security Policy is partial

A CSP header was detected but could not be fully evaluated. A complete, strict CSP reduces risk of cross-site scripting attacks.

How to fix: Review your CSP and tighten directives to reduce allowed sources.

About this report: ClearScan performs external-only, passive scans of publicly visible security signals. No data was accessed inside google.com's systems. Findings reflect what is visible from the public internet — some gaps may have compensating controls not detectable externally. This report does not constitute a security audit or certification.

See your own score

Run a free scan on your domain in under 10 seconds — no account needed. The full report checks everything here for your business, in the same plain English.

Full report includes a guided self-assessment, a PDF download, and a cyber-insurance readiness PDF.

© 2026 ClearScan · External scan only · No sensitive data accessed