What Ward checks
Ward runs 17 checks, grouped in 5 areas, and can report 88 kinds of findings. Open any check to see every finding it can produce, explained the same way as in your dashboard.
Protection against email spoofing (SPF, DKIM, DMARC) and encryption in transit.
Website and certificates
HTTPS certificate, website security settings and visible technologies.
- HTTPS certificateHTTPS certificate for your domain and www: issuer, validity, chain, cipher, key, signature and whether it still accepts TLS 1.0/1.1; HSTS preload if the homepage asks for it. It also checks the expiry and name of the certificates of subdomains already known from public certificate logs (at most 15, one TLS handshake each).14 kinds of findings
- Public websiteA single visit to your homepage, like a browser: redirect to HTTPS, HSTS, security headers, visible versions, technologies, cookies, forms, legal pages and signs of a hacked site (hidden spam, redirects to another domain).14 kinds of findings
- Standard public filesReads the three files a website publishes on purpose at fixed, standard locations: robots.txt, sitemap.xml and /.well-known/security.txt. One request to each, nothing more. It doesn't open any of the paths they mention or try others: Ward doesn't probe paths.4 kinds of findings
- Cookies and trackersTrackers (analytics, advertising, session recording) and tracking cookies that your homepage switches on before asking for consent, and whether a cookie consent tool is present. Homepage only; a guide, not an audit.3 kinds of findings
- JavaScript librariesJavaScript libraries (jQuery, Bootstrap, AngularJS and others) with a visible version in your homepage HTML, and their known vulnerabilities according to a local database. No script is downloaded.2 kinds of findings
- Certificate issuanceCertificate authorities that issued certificates for your domain in the last 90 days (public certificate logs), and whether they match the ones your CAA record allows or the ones you have always used.2 kinds of findings
Exposed infrastructure
Published subdomains and services reachable from the internet.
- SubdomainsSubdomains that appear in public certificate logs (Cert Spotter, with crt.sh as a backup), possible takeovers and sensitive names. We don't guess names from a dictionary.3 kinds of findings
- Indexed contentSearches the Common Crawl index and, if available, Brave Search for addresses of your domain that point to backups and data dumps, logs, code repositories, configuration files, sign-in or admin panels, API documentation, directory listings or internal documents. It only queries those sources (the search engines, not your server): it doesn't open any of those addresses or try others.2 kinds of findings
Domain
Domain registration, expiry, transfer protection and DNSSEC.
Reputation and impersonation
Blocklists, lookalike domains, data breaches and ransomware.
- BlocklistsWhether your IPs (website, email and SPF senders) and your domain are on public email blocklists (DNSBL), telling a real listing apart from a rejected query. The report says which lists were checked.1 kind of finding
- Lookalike domainsGenerates variations of your domain (missing, repeated or swapped letters, neighboring keys, look-alike characters, hyphens and other domain endings) finds which of them are registered with a website or email and, for up to 10 that have a website, makes a single visit to the homepage to see whether it copies yours.2 kinds of findings
- Credentials in public codeSearches public GitHub code for your domain next to passwords, API keys or connection strings. The secret is never stored.1 kind of finding
- RansomwareLooks for your domain and your company name on ransomware groups' leak sites, using recent data from RansomLook and RansomFeed that we download every few hours and match on our servers.1 kind of finding
- Website flagged as dangerousWhether your website (domain and “www”) is listed as possibly dangerous by Google Web Risk (malware, phishing), or your domain or any of its subdomains is on Phishing.Database. It only queries those lists; nothing else on your website is visited.2 kinds of findings
- IPs attacking othersWhether any of your public IPs (up to 30) is in a network marked as hijacked or used for crime (DROP list), on the CINS list of addresses that have attacked other systems, or is a Tor exit node. The lists are downloaded every day and matched on our servers.5 kinds of findings