惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Webroot Blog
Webroot Blog
罗磊的独立博客
B
Blog RSS Feed
大猫的无限游戏
大猫的无限游戏
G
Google Developers Blog
WordPress大学
WordPress大学
T
Tailwind CSS Blog
U
Unit 42
B
Blog
Stack Overflow Blog
Stack Overflow Blog
J
Java Code Geeks
Vercel News
Vercel News
博客园 - Franky
T
Tenable Blog
F
Fortinet All Blogs
P
Privacy International News Feed
P
Palo Alto Networks Blog
Security Latest
Security Latest
爱范儿
爱范儿
K
Kaspersky official blog
Engineering at Meta
Engineering at Meta
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
V
V2EX
The Cloudflare Blog
H
Help Net Security
NISL@THU
NISL@THU
酷 壳 – CoolShell
酷 壳 – CoolShell
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
The GitHub Blog
The GitHub Blog
V
Visual Studio Blog
月光博客
月光博客
C
CERT Recently Published Vulnerability Notes
L
Lohrmann on Cybersecurity
Latest news
Latest news
A
Arctic Wolf
C
Cisco Blogs
宝玉的分享
宝玉的分享
Cyberwarzone
Cyberwarzone
Y
Y Combinator Blog
O
OpenAI News
S
Security Archives - TechRepublic
www.infosecurity-magazine.com
www.infosecurity-magazine.com
I
InfoQ
云风的 BLOG
云风的 BLOG
PCI Perspectives
PCI Perspectives
C
CXSECURITY Database RSS Feed - CXSecurity.com
Recorded Future
Recorded Future
V
V2EX - 技术
D
DataBreaches.Net

Show HN

GitHub - djadmin/fort: macOS CLI: endpoint security audit + SOC 2 readiness reports GitHub - jmilinovich/grove: Open-source MCP server over a git-backed Obsidian vault. Single-user, self-host. Six tools, hybrid search, provenance/blame, auto-link discovery. GitHub - Astralchemist/rig: Local-first semantic knowledge graph with magnetic-pull retrieval GitHub - sediman-agent/OpenSkynet: Your 24/7 Terminator CSP Radar GitHub - wartzar-bee/tokenscope: See what your AI-coding session actually cost — and what is eating your context. Local, read-only CLI for Claude Code. CSP Radar GitHub - awebai/aweb-team-coord-worktrees: An aweb team template for a minimum team with a permanent coordinator and worktrees with local developers. GitHub - fujibee/agmsg GitHub - lucastononro/notify: 100% local, free, offline attention skill for Claude Code: plays a sound and speaks a short status update when a long task finishes, blocks, or needs a decision. GitHub - sebastianwessel/skills: AI Skills tivatdoar / workout-to-work · GitLab Release v1.0.0-alpha7 · pantoniou/libfyaml SE Coverage Planner - free territory and workload planning GitHub - enumura1/py-sql-cleaner: Find, format, and safely extract embedded SQL from Python files. GitHub - intent-bench/intent-bench: Intent fulfillment benchmark for agentic AI engineering GitHub - steveking-gh/firmion: Firmion is DSL and engine for firmware image generation. GitHub - villagesql/villagesql-skills: Agent skills for VillageSQL - gemini-cli-extension; claude-code-plugin GitHub - 0gsd/enough: a personal language system for planning, writing, and translation. GitHub - Kaelio/ktx: ktx is an executable context layer for data and analytics agents 🐙 Allow Claude Code, Codex, and any AI agent to query data accurately through MCP with skills, memory and a semantic layer GitHub - ThatXliner/xtras: Xliner's Claude Code Skills GitHub - flightdeckhq/flightdeck: Observability and control plane for AI agents. GitHub - search-router/simple-search: Open-source reference app on top of the Search Router API: FastAPI + Jinja metasearch service with pluggable backends, deterministic mocks (no API key needed), RTL UI, Redis cache, and a demo ads cabinet. CSP Radar GitHub - Light-Heart-Labs/DreamServer: Turn your PC, Mac, or Linux box into an AI server. LLM inference, chat UI, voice, agents, workflows, RAG, and image generation. GitHub - Diplomat-ai/diplomat-agent-ts: What can your TypeScript AI agent do to the real world? Scan your code. See which tool calls have zero checks Code Block Selector - Visual Studio Marketplace Prometheus dependency graph — interactive showcase | Riftmap Show HN: I made a vi-like modal keyboard plugin for Figma GitHub - run-llama/liteparse: A fast, helpful, and open-source document parser GitHub - dalemyers/Roar: A macOS CLI tool for notifications GitHub - district-solutions/open-agent-tools-coder: Enables small-to-large self-hosted ai models to use local source code when running tool-calling agentic workloads. We actively data mine 20,900+ (2+ TB) popular github repos using large and small ai models to create reuseable: json, markdown and parquet files for local-first tool-calling models. GitHub - progapandist/stripeek: A local TUI proxy for real-time Stripe API debugging, built for navigating complex payloads fast. GitHub - sir1st/hermes-desktop: All-in-one cross-platform desktop app for Hermes Agent — bundles Python + hermes-agent + hermes-web-ui GitHub - astefanutti/shaderbang: Shebang for Shaders Show HN: Generate Claude Code Workflows using Spec Driven Development approach GitHub - nixys/nxs-universal-chart: The Helm chart you can use to install any of your applications into Kubernetes/OpenShift Show HN: AI agents for UK GDAD PCF roles and their skills The Two Pillars: Mixer Mode and Meta-Software in the Reorganization of Software Work After AI GitHub - JaiCode08/teleport-env What 1,000+ Harness Experiments Taught Me About Self-Improving Agents Show HN: Liiists, a Markdown-first, iOS and CLI list app SwiperTab – Get this Extension for 🦊 Firefox (en-US) GitHub - kouhxp/fftext: Summarize, explain, fact-check, or translate any text, URL, or file. No GPU. No cloud. One command GitHub - sweetpad-dev/sweetpad: Develop Swift/iOS projects using VSCode GitHub - dogmaticdev/IRON: IRON a.k.a. Intermediate Representation Object Notation is a Interpreter/Database that is used to create Programming Languages. GitHub - sjhalani7/vaen: Package your AI coding harness into a portable .agent file, and share it across repos, teams, & the community without ever having to copy-paste instructions, skills, MCP config, or secrets. Show HN: Gandalf the Grader Show HN: Citadeld – replay any CI failure locally from a single file GitHub - tdortman/cuSBF: High-Performance GPU Super Bloom Filter coral-ai/claude-code-token-xray at main · Coral-Bricks-AI/coral-ai GitHub - ulyssestenn/funes: Funes is a Git-based framework for LLM-managed knowledge work: an AI Librarian ingests raw sources, builds an interlinked Markdown knowledge base, and uses it to produce cited reports, analyses, and other outputs. GitHub - ThatXliner/gah: Git Add Hunk, built for agents to use GitHub - harmont-dev/harmont-cli: Command-line client for the Harmont CI platform GitHub - brooksmcmillin/mcp-authflow: OAuth 2.0 Authorization Server framework for MCP servers GitHub - javaid-codes/audit-supply-chain-agents GitHub - amorey/gochan: A small library of common channel architectures for Go, inspired by Rust GitHub - arifozgun/OpenGem: Free, Open-Source AI API Gateway with Gemini, OpenAI & Anthropic Compatibility in 1 file GitHub - Pranesh950/BioPetals: 🌸 Run BIOxAI models at home, BitTorrent-style. Fine-tuning and inference up to 10x faster than offloading GitHub - cnguyen14/bounty-doctor: Diagnose a GitHub bounty issue before you waste hours: detects honeypot scam repos, AI-bot attempt swarms, and stale contests. Show HN: CoreMCP – MCP Server for On-Prem DBs Show HN: KittyHTML – Render HTML/CSS as an inline image in your terminal GitHub - bingud/filemat: Web-based file manager Show HN: TruthLens – Free multi-signal deepfake image detector GitHub - apexlocal-jz/claude-usage-tray: Windows system-tray app showing your Claude Code rate-limit usage at a glance. Zero deps, ~300 lines of PowerShell. Cross-IDE (works regardless of VS Code, Cursor, plain terminal). Release v0.1.2.1 · kouhxp/yapsnap GitHub - noopolis/moltnet: Self-hostable chat network for AI agents. Pre-built bridges for Claude Code, Codex, and the Claws. Rooms, DMs, history. No Slack bots, no Matrix, no glue code. GitHub - tamerh/enju: Coordinating Humans, AI Agents, and Compute as Peers on a Shared Workflow Graph Show HN: Continuity-auth – Respect-weighted rate limits for the open web GitHub - luml-ai/luml: AI lifecycle platform where engineers and agents track experiments, train models, and ship to production. GitHub - mrdanielcasper/CoreTex: A UNIX-inspired, biomimetic, flat-file AI harness and knowledge engine. GitHub - clemg/pierre-github: Pierre's diffs.com and trees.software for Github GitHub - lyriks-io/unspaghettit: Behavior-driven AI development without prompt spaghetti. GitHub - sofumel/claude-handoff-revive: Resume Claude Code work after rate/usage/context limits without replaying the prior transcript. Auto-saves at 90%/95% usage. Plugin-installable, 10 languages. GitHub - dotexorg/saferpc: Typed, end-to-end encrypted RPC over any bidirectional channel. GitHub - BeeZeeAgent/beezee: Agent harness orchestration Legato Next.js Boilerplate for Internal Tools · CoreUI GitHub - clark-labs-inc/clark-hash: Clark Hash, 32x smaller searchable sketches for embeddings GitHub - ZeroPointRepo/youtube-mcp: The fastest YouTube transcript + YouTube search MCP for AI agents. Try for free. Typing Mastery — climb toward 100+ WPM, deliberately GitHub - Andebugulin/Awareen GitHub - StackOneHQ/stack-nudge We hardened an LLM agent. Each defense we added made it more exploitable. GitHub - octelium/cordium: Open-source, general-purpose sandbox platform for devs and AI agents that provides identity-based secure access to infrastructure without credentials. GitHub - zoharbabin/web-researcher-mcp: MCP server (Go) for AI assistants: web search, content extraction, academic/patent/news research. Multi-provider routing, 4-tier scraping, search lenses. Works with Claude, Cursor, and any MCP client. GitHub - scanaislop/aislop: Catch the slop AI coding agents leave in your code: narrative comments, swallowed exceptions, as-any casts, dead code, oversized functions. 50+ rules across 7 languages (TypeScript, JavaScript, Python, Go, Rust, Ruby, PHP). Sub-second, deterministic, no LLM at runtime. MIT-licensed. GitHub - kouhxp/cheap-im: CPU-only voice agent approximating Thinking Machines' Interaction Models demo GitHub - unprovable/OrchidMantis: Orchid Mantis — standalone framework for Zero-Knowledge Proofs of eXploit (ZKPoX). GitHub - CarpseDeam/Aura-IDE: An AI coding harness that shaped itself - Planner/Worker agents, repo awareness, surgical edits, validation, recovery, and safe diff approvals. GitHub - chojs23/concord: A feature-rich TUI client for Discord GitHub - aerf-spec/aerf: Agent Evidence Receipt Format (AERF) — an open specification for tamper-evident, independently verifiable records of AI agent actions. GitHub - Jwrede/tokentoll: Catch LLM cost changes in code review. Infracost for LLM spend. GitHub - samchon/ttsc: A `typescript-go` toolchain for compiler-powered plugins and type-safe execution + 500x faster lint integrated into compiler GitHub - Higangssh/homebutler: 🏠 Manage your homelab from chat. Single binary, zero dependencies. GitHub - Bajusz15/beacon: Open-source agent for secure remote access, monitoring, and deploys across home-lab and self-hosted machines like Raspberry Pi, N100, or any Linux server. Open web based TTY or tunnel Home Assistant and other local services securely without opening ports. BigTech AI News - Chrome 应用商店 GitHub - vinhnx/VTCode: VT Code is an open-source coding agent with LLM-native code understanding and robust shell safety. Supports multiple LLM providers with automatic failover and efficient context management. GitHub - familiar-software/familiar: Let AI watch you work. Familiar lets your AI update its memory, skills, and knowledge by watching your screen. make sidebar/address bar rounded corner toggleable
Domain Intelligence Scanner – DNS, Email, SSL & Website Security Audit | SwissArmyTechTools
py93 · 2026-06-16 · via Show HN

Complete security assessment for any domain — DNS, DNSSEC, email authentication, SSL/TLS certificates, and website security headers in a single scan. Built for MSPs, IT admins, and security professionals.

How the Domain Intelligence Scanner works

Enter any domain name and the scanner performs five parallel security checks simultaneously:

  • DNS & DNSSEC — Retrieves nameservers, CAA records, and verifies DNSSEC signing via two independent resolvers (Cloudflare 1.1.1.1 and Google Public DNS)
  • Email Security — Queries SPF, DKIM (scanning common selectors), and DMARC records and analyses policy strength
  • SSL/TLS — Performs a live TLS handshake to inspect the certificate, verify validity, check expiry, and detect HSTS configuration
  • Security Headers — Fetches the HTTP response headers and scores CSP, HSTS, X-Frame-Options, X-Content-Type-Options, and Referrer-Policy

Results are scored using a weighted model — Email Security (30%), DNS Security (25%), SSL/TLS (25%), Website Security (20%) — and combined into an overall score and A–F grade.

Common uses

The Domain Intelligence Scanner is designed for security-minded assessments where you need a fast, structured view of a domain's security posture:

  • MSP prospect assessments — run before a sales or onboarding meeting to understand a client's security gaps
  • Email deliverability troubleshooting — instantly see whether SPF, DKIM, and DMARC are correctly configured
  • Security baseline checks — verify a domain meets minimum security standards after a migration or handoff
  • Pre-launch validation — confirm all security controls are in place before launching a new website or domain
  • Competitive research — check competitors' or vendor domains for security posture
What does the Domain Intelligence Scanner check?

The scanner performs five parallel checks: DNS security (DNSSEC status, nameserver redundancy, CAA records), email security (SPF, DKIM, DMARC policy analysis), SSL/TLS certificate health (validity, expiry, TLS version, HSTS), website security headers (CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy), and DNSSEC chain-of-trust validation via two independent resolvers — Cloudflare 1.1.1.1 and Google Public DNS. Results are scored by category, combined into an overall A–F grade, and presented as an executive summary, prioritised findings, and actionable recommendations.

Do I need DNSSEC?

DNSSEC is not required but is strongly recommended for any domain that matters. Without it, DNS responses can be forged on the network path — silently redirecting your users to a malicious server without any visible warning (DNS cache poisoning). Cloudflare, Amazon Route 53, and Google Cloud DNS all support DNSSEC with a single toggle. The main extra step is publishing the DS record at your registrar, which typically takes 15–30 minutes.

What is a good domain security score?

Scores of 90–100 (Grade A) indicate excellent security posture. Scores of 75–89 (Grade B) represent good security with minor improvements available. Scores of 60–74 (Grade C) show fair security with several gaps to address. Scores of 45–59 (Grade D) indicate poor security with significant issues present. Scores below 45 (Grade F) indicate critical deficiencies requiring immediate attention. Most production domains without dedicated security hardening score in the C–D range.

What are CAA records and why do they matter?

CAA (Certification Authority Authorization) records specify which Certificate Authorities are permitted to issue SSL certificates for your domain. For example, 0 issue "letsencrypt.org" restricts issuance to Let's Encrypt only. Without CAA records, any CA in the world can issue a certificate for your domain — a risk if a CA is compromised or makes an issuance error. They take about 15 minutes to add at your DNS provider and require no changes to your web server or application.

How is the overall score calculated?

The overall score is a weighted average of four category scores: Email Security (30%), DNS Security (25%), SSL/TLS (25%), and Website Security (20%). Email is weighted highest because domain spoofing via email is one of the most impactful attack vectors for most organisations. Each category score reflects specific controls — DMARC p=reject earns 50 of the 100 email security points; DNSSEC fully signed earns 50 of the 100 DNS security points.

What does it mean if SSL details are unavailable?

The SSL/TLS check uses a raw TCP socket connection to inspect the certificate at the protocol level. Cloudflare-proxied domains and CDN-fronted hosts block this approach — Cloudflare's runtime cannot open outbound TCP sockets to its own IP ranges by design. When blocked, the scanner confirms HTTPS is reachable and estimates the SSL score from HSTS, but cannot extract certificate details. Use the standalone SSL/TLS Certificate Checker from your browser for full certificate information on these hosts.

What is the difference between SPF, DKIM, and DMARC?

SPF (Sender Policy Framework) defines which mail servers are authorised to send email for your domain — a DNS TXT record listing permitted IPs or service includes. DKIM (DomainKeys Identified Mail) adds a cryptographic signature to outbound emails so receivers can verify the message was authorised and not modified in transit. DMARC ties them together with a published policy — p=none, p=quarantine, or p=reject — that tells receiving servers what to do with mail failing both checks. All three are needed for full email authentication and anti-spoofing protection.

Why does the scan take several seconds?

The scanner runs five parallel checks — DNS records, DNSSEC chain validation, email authentication (SPF/DKIM/DMARC), SSL/TLS certificate inspection, and security headers analysis — all simultaneously. The SSL/TLS check requires a full TLS handshake, which is the slowest individual operation. Because all checks run in parallel, the total time is determined by the slowest single check rather than the sum. Most scans complete in 5–10 seconds.

Why is DMARC so important for email security?

DMARC tells receiving mail servers what to do with email that fails SPF and DKIM checks. Without DMARC set to p=reject or p=quarantine, attackers can send phishing email appearing to come from your domain and it will be delivered normally. DMARC with p=reject is the only configuration that fully prevents domain spoofing. Even with both SPF and DKIM present, a missing or p=none DMARC record provides zero enforcement — your domain can still be used in business email compromise (BEC) and phishing attacks.

How often should I scan my domain?

Scan any time you make DNS, email, or hosting changes — and at minimum monthly for production domains. Certificate expiry, new email sending services, DNS provider migrations, and DMARC policy updates can shift your security posture without you noticing. MSPs typically scan client domains before onboarding, after any migration or handoff, and on a quarterly review cycle to catch configuration drift.

Can attackers spoof my domain?

Yes — without DMARC set to p=reject or p=quarantine, attackers can send email that appears to come from your domain and it will reach recipients' inboxes. This technique is used in phishing, business email compromise (BEC), and brand impersonation campaigns. SPF and DKIM alone do not prevent this — they provide authentication signals that only DMARC enforces. The scanner flags any domain without a DMARC enforcement policy as high risk regardless of SPF and DKIM configuration.

Can MSPs use this report for client assessments?

Yes — the scanner is built with MSP use cases in mind. Run a scan before a prospect meeting to identify quick wins and start a conversation. Use the Executive Summary and Recommendations sections with non-technical stakeholders — the score and grade provide an at-a-glance health indicator, and each recommendation includes impact, difficulty, and estimated effort so you can scope remediation work and set realistic client expectations.

What security issue should I fix first?

Fix Critical findings immediately — BOGUS DNSSEC and expired SSL certificates can make your domain unreachable. After that, address High findings by effort: DMARC p=reject, SPF, and HSTS are all Easy/15–30 minutes. DNSSEC and Content-Security-Policy take slightly more effort but have high impact. The Recommendations section orders all actions by impact-to-effort ratio so you always know what to prioritise next.

Why does DKIM sometimes show as not found?

DKIM keys are published at a selector-specific subdomain such as selector1._domainkey.yourdomain.com. There is no standard way to discover all selectors — the scanner probes a list of common names (google, selector1, selector2, default, k1, mail, and others). If your provider uses a non-standard selector, DKIM will show as not found even if signing is active. Check your email provider's documentation for the correct selector name and confirm using the SPF / DKIM / DMARC Validator.

Can this tool help identify compliance gaps?

Yes. Many frameworks — CIS Controls, NIST CSF, ISO 27001, and SOC 2 — require technical controls this scanner covers: email authentication (SPF/DKIM/DMARC maps to CIS Control 9), encryption in transit (TLS/HSTS), DNS security (DNSSEC), and web security headers (CSP/XFO). The scanner does not produce a formal compliance report, but its findings map directly to common technical controls and serve as concrete evidence for gap assessments and remediation tracking.