Security Analysis
turbo.cr
C
125 / 215
2 critical2 high2 medium
Basic Security
10/40 (25%)DNSSEC Enabledhigh
DNSSEC protects against DNS spoofing and cache poisoning
→ Enable DNSSEC to protect against DNS spoofing and cache poisoning attacks. Contact your domain registrar to enable DNSSEC.
Multiple Nameservers
Multiple nameservers provide redundancy
Nameserver Diversitylow
Nameservers on different networks improve resilience
→ All nameservers appear to be from the same provider. Consider using nameservers from different providers for better resilience.
Record Security
0/45 (0%)CAA Recordshigh
CAA restricts which CAs can issue certificates
→ Add CAA records to specify which Certificate Authorities are allowed to issue certificates for your domain. Example: 0 issue "letsencrypt.org"
SPF Recordcritical
SPF prevents email spoofing
→ Add an SPF record to prevent email spoofing. Example: v=spf1 include:_spf.google.com -all
DMARC Recordcritical
DMARC protects against phishing
→ Add a DMARC record at _dmarc.yourdomain.com. Example: v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com
DKIM Presencelow
DKIM can't be verified from public DNS without knowing your provider's selector (records live at selector._domainkey.yourdomain.com)
→ We couldn't verify DKIM from public DNS — this is normal even when DKIM is working. Confirm it's enabled with your email provider.
Advanced Security
15/25 (60%)Mail Server Configurationmedium
Multiple MX records provide email redundancy
→ No MX records found. If you use email, configure MX records pointing to your mail server.
SOA Record Configuration
SOA record with reasonable TTL/refresh values
IPv6 Support
AAAA records enable IPv6 connectivity
Domain Reputation
50/50 (100%)Typosquatting Check
Domain does not mimic protected brands
Domain Blacklist Status
Domain checked against spam and malware blacklists (Spamhaus DBL, SURBL, URIBL)
IP Blacklist Status
Server IP addresses checked against spam and abuse blacklists (Spamhaus ZEN, SpamCop, Barracuda)
Threat Detection
50/55 (91%)DGA Detection
Domain Generation Algorithm detection
DNS Tunneling Detection
Detection of data exfiltration via DNS
Fast-Flux Detection
Detection of rapidly changing DNS infrastructure
Domain Age Checkmedium
Detection of newly registered domains
→ Domain appears to be newly registered. Exercise caution with new domains.