RedScore.ai

Blog

RedScore security guides

Scanner explainers, launch checklists, and fix-first guidance for founders and operators. Written for SEO and answer engines with direct answers up front.

Email Security·2 min read·2026-06-14

DMARC, SPF, and DKIM explained for founders

DMARC, SPF, and DKIM are the three DNS records that stop email spoofing on your domain. Here is what each one does and how to check them.

Read post
Email Security·2 min read·2026-06-14

How to check if your domain can be spoofed

Check if your domain can be spoofed by reviewing DMARC, SPF, and DKIM on your live domain. RedScore runs that outside-in email auth check in about 60 seconds.

Read post
Checklists·2 min read·2026-06-14

Startup security checklist before your first customer

Run this startup security checklist on your production domain before your first customer signs up. Public TLS, headers, DNS, and email auth in about 60 seconds.

Read post
Checklists·2 min read·2026-06-14

Vendor security review checklist

Use this vendor security review checklist to evaluate a supplier's public security posture before signing. TLS, headers, DNS, and email auth in about 60 seconds.

Read post
Checklists·2 min read·2026-06-14

Website security scan checklist before launch

Run this website security scan checklist on your production domain before launch. TLS, headers, DNS, email auth, and exposure in about 60 seconds.

Read post
Email Security·2 min read·2026-06-14

What does a DMARC checker test?

A DMARC checker reads your public DMARC DNS record and checks whether your domain enforces email authentication or just monitors failures.

Read post
Checklists·1 min read·2026-06-08

Firebase app security checklist

Firebase app security starts on your public domain: TLS, headers, DNS, email auth, exposure. This checklist runs in about 60 seconds, no console access.

Read post
Checklists·1 min read·2026-06-08

Next.js security headers checklist

Verify Next.js security headers on production, not in your config files. HSTS, CSP, cookies, and related signals from an outside-in scan.

Read post
Checklists·1 min read·2026-06-08

Vibe-coded app security checklist

Shipped with Cursor, Lovable, or Bolt? Run this vibe-coded app security checklist on your production domain before demos, payments, or user data.

Read post
Security Scanners·1 min read·2026-06-08

What is a Supabase security scanner?

A Supabase security scanner checks public signals on the domain your app runs on. TLS, headers, DNS, email auth, exposure. Not RLS or database rules.

Read post
Security Scanners·1 min read·2026-06-08

What is a Vercel security scanner?

A Vercel security scanner checks the public signals on your live domain: TLS, headers, DNS, email auth, and exposure. No repo access required.

Read post
Checklists·1 min read·2026-06-08

WordPress security scan checklist

Run this WordPress security scan checklist on your live domain first: TLS, headers, DNS, email auth, exposure, reputation. No plugin install.

Read post