Security Analysis

bni.co.id

C
135 / 215
1 critical2 high3 medium

Basic Security

10/40 (25%)
DNSSEC Enabledhigh
DNSSEC protects against DNS spoofing and cache poisoning
Enable DNSSEC to protect against DNS spoofing and cache poisoning attacks. Contact your domain registrar to enable DNSSEC.
Multiple Nameservers
Multiple nameservers provide redundancy
Nameserver Diversitylow
Nameservers on different networks improve resilience
All nameservers appear to be from the same provider. Consider using nameservers from different providers for better resilience.

Record Security

15/45 (33%)
CAA Recordshigh
CAA restricts which CAs can issue certificates
Add CAA records to specify which Certificate Authorities are allowed to issue certificates for your domain. Example: 0 issue "letsencrypt.org"
SPF Record
SPF prevents email spoofing
DMARC Recordcritical
DMARC protects against phishing
Add a DMARC record at _dmarc.yourdomain.com. Example: v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com
DKIM Presencelow
DKIM can't be verified from public DNS without knowing your provider's selector (records live at selector._domainkey.yourdomain.com)
We couldn't verify DKIM from public DNS — this is normal even when DKIM is working. Confirm it's enabled with your email provider.

Advanced Security

20/25 (80%)
Mail Server Configuration
Multiple MX records provide email redundancy
SOA Record Configuration
SOA record with reasonable TTL/refresh values
IPv6 Supportlow
AAAA records enable IPv6 connectivity
No IPv6 (AAAA) records found. Consider adding IPv6 support for future-proofing.

Domain Reputation

40/50 (80%)
Typosquatting Check
Domain does not mimic protected brands
Domain Blacklist Status
Domain checked against spam and malware blacklists (Spamhaus DBL, SURBL, URIBL)
IP Blacklist Statusmedium
Server IP addresses checked against spam and abuse blacklists (Spamhaus ZEN, SpamCop, Barracuda)
IP address(es) listed on blacklists: 45.223.66.109 (Spamhaus ZEN); 45.223.65.109 (Spamhaus ZEN). This may indicate the IP was used for spam or is on a shared hosting platform.
Reputation Confidence Alertmedium
Aggregate confidence score from multiple blacklist sources
High confidence (26%) that this domain/IP may be associated with malicious activity. Review blacklist details and take action.

Threat Detection

50/55 (91%)
DGA Detection
Domain Generation Algorithm detection
DNS Tunneling Detection
Detection of data exfiltration via DNS
Fast-Flux Detection
Detection of rapidly changing DNS infrastructure
Domain Age Checkmedium
Detection of newly registered domains
Domain appears to be newly registered. Exercise caution with new domains.