Security Report
google.com
Scanned June 22, 2026 · General Business · External scan only
12
Checks run
3
Passed
6
Findings
Email Security
PartialSPF (Sender Policy Framework)
v=spf1 include:_spf.google.com ~all
DKIM (DomainKeys Identified Mail)
Note: No DKIM selector detected at common selectors — google.com uses a custom selector not checked by automated scanners.
DMARC policy
v=DMARC1; p=reject; rua=mailto:mailauth-reports@google.com
DMARC policy is set to p=reject — the strictest level. Emails that fail authentication are rejected outright rather than quarantined. SPF record correctly scopes authorized senders.
TLS / SSL Encryption
PassedClearScan rating: Secure
Security Headers
GapStrict-Transport-Security (HSTS)
X-Content-Type-Options
X-Frame-Options
Content-Security-Policy
Referrer-Policy
google.com (root) redirects to www.google.com — HSTS and X-Content-Type-Options are present on the www subdomain. Redirect responses do not include these headers.
Website Software
Not measuredgoogle.com is served through Google’s own front end, which hides the software running behind it — we couldn’t determine what it runs.
This check looks only at your public website — the software your site discloses about itself, and whether that exact version has publicly documented security flaws. It does not examine network services, remote-access tools, or any device on your office network.When a site doesn't disclose a version we can trust, we look nothing up and report no result rather than guess — it stays out of the score, never counted against you.
Breach Exposure
Partial0 breaches found for @google.com
Findings & Recommendations
Prioritized by severity — this is the list you hand to whoever manages your IT.
HSTS not detected on root domain
The Strict-Transport-Security header was not found on the root domain response. Visitors who type "google.com" without HTTPS may be susceptible to downgrade attacks before the redirect fires.
How to fix: Ensure HSTS is set on the root domain response, not just after redirect. Add a preload entry if possible.
X-Content-Type-Options header missing
Without this header, some browsers may try to sniff content types, potentially executing malicious content as a different type than intended.
How to fix: Add X-Content-Type-Options: nosniff to all server responses including redirect responses.
DKIM could not be verified
Automated DKIM scanning checks common selectors. A custom or non-standard selector could not be found. If DKIM is configured with a non-standard selector, this finding can be ignored.
How to fix: Confirm DKIM is enabled in your email provider settings and that the selector is published in DNS.
Website software version could not be determined
This site is served through a front end that hides the software running behind it, so we could not check that software against public vulnerability databases. That is not a pass and not a mark against the site — it simply could not be measured, so it is excluded from the score.
How to fix: Nothing to do. If you want the check to run, ask your host whether the origin server can report its version.
TLS worth an independent second opinion
ClearScan rates this site Secure: the certificate is trusted, covers this address, and only modern TLS versions are accepted. We check the things that break a site for real visitors, not every cipher-level detail.
How to fix: Ask whoever manages the site to review your TLS settings; ssllabs.com/ssltest gives an independent second opinion.
Content Security Policy is partial
A CSP header was detected but could not be fully evaluated. A complete, strict CSP reduces risk of cross-site scripting attacks.
How to fix: Review your CSP and tighten directives to reduce allowed sources.
About this report: ClearScan performs external-only, passive scans of publicly visible security signals. No data was accessed inside google.com's systems. Findings reflect what is visible from the public internet — some gaps may have compensating controls not detectable externally. This report does not constitute a security audit or certification.
See your own score
Run a free scan on your domain in under 10 seconds — no account needed. The full report checks everything here for your business, in the same plain English.
Full report includes a guided self-assessment, a PDF download, and a cyber-insurance readiness PDF.