Learn
Plain-English security, one finding at a time.
Every Vantyris scan produces findings with a plain-English explanation, a concrete fix, and an ownership hint. The articles below go further: the why behind each finding, the common gotchas, the references your developer or web host will recognise. Written for the business owner who runs the site, not for the security engineer.
Email authentication: SPF, DKIM, DMARC, BIMI, MTA-STS. If you fix one area first, make it this one: it's where impersonation happens.
- 2026-04-01
DMARC p=none does not stop phishing. Here's what to do instead.
DMARC p=none collects reports but blocks nothing. When it is safe to move to p=quarantine, and the exact DNS record to publish.
- 2026-05-01
What is DMARC, and why every business with a domain needs one.
DMARC stops attackers from sending email as your domain. Why every business with a domain needs it, and the one DNS record to add.
- 2026-06-06
SPF records, explained: the first line of defence against email spoofing.
SPF lists the servers allowed to send email for your domain. Without it, attackers can spoof your address. The TXT record to add and the usual mistakes.
- 2026-04-29
DKIM: the cryptographic signature that completes your email authentication trio.
DKIM adds a tamper-proof signature to every email you send, so receiving servers can check it really came from you. How it works and the record to add.
- 2026-05-13
MTA-STS: forcing TLS on every email destined for your inbox.
MTA-STS makes servers that send to your domain use TLS, so inbound mail cannot be downgraded. One DNS record plus one HTTPS file.
- 2026-06-07
BIMI: putting your brand logo next to your sender name in Gmail and beyond.
BIMI puts your verified logo next to your sender name in major inboxes. Requires DMARC at quarantine or stricter, a VMC certificate, and one DNS record.
TLS
Transport security: HTTPS, certificate management, TLS protocol versions. The padlock in your visitor's browser, explained.
- 2026-04-19
HTTPS for small business: how to enable it in 15 minutes.
Chrome shows a 'Not secure' warning to every visitor of an HTTP-only site. Here's how to enable HTTPS in 15 minutes with a free Let's Encrypt certificate.
- 2026-04-18
TLS 1.0 and 1.1: turn them off. Here's why and how.
TLS 1.0 and 1.1 are deprecated and gone from modern browsers. Why your server should offer only TLS 1.2 and 1.3, and the one-line fix.
- 2026-05-20
Your TLS certificate has expired. Here's how to restore the site fast.
An expired TLS certificate blocks every visitor with a full-screen browser warning. Here's how to renew immediately and prevent it happening again.
- 2026-05-25
Short HSTS max-age: what it really means, and how to extend it safely.
A short HSTS max-age narrows the protection window but rarely means a live attack. When it matters, and the server snippet that fixes it safely.
Headers
HTTP response headers that tell the browser how to protect your visitors. CSP, HSTS, X-Frame-Options, and the supporting cast.
- 2026-06-10
HSTS: the security header that locks HTTPS on for good.
HSTS tells browsers to always use HTTPS on your domain, which blocks downgrade attacks. The header to add and the max-age to start with.
- 2026-05-12
Content Security Policy: the header that stops most XSS attacks dead.
CSP blocks injected scripts and other attacks that XSS protections miss. Here's how to enable a useful policy without breaking your site.
- 2026-05-19
X-Frame-Options and frame-ancestors: the anti-clickjacking header.
X-Frame-Options stops other sites from showing yours inside a frame, where attackers can lay invisible buttons over it. The header to add.
- 2026-05-03
SameSite + Secure cookies: the two attributes every session cookie needs.
Cookies without the SameSite and Secure flags can be stolen by other sites or read on hostile Wi-Fi. Two attributes on every cookie, and how to set them.
- 2026-05-06
Permissions-Policy: explicitly disabling browser features your site doesn't use.
Permissions-Policy lets you switch off browser features your site never uses, such as the camera or microphone. One header, safe by default.
- 2026-06-16
X-Content-Type-Options: nosniff. The one-line defensive header.
X-Content-Type-Options: nosniff tells browsers not to guess a file's type, which stops one class of XSS attack. A five-minute fix.
DNS
DNS records that protect your domain: CAA for certificate issuance, DNSSEC, MX hygiene, and the basics.
- 2026-06-15
CAA records: the DNS entry that decides who can issue your TLS certificates.
A CAA record limits which certificate authorities can issue certificates for your domain. Without one, any CA can. How to set one up.
- 2026-06-05
DNSSEC: cryptographic signing for your DNS, explained plainly.
DNSSEC signs your DNS records so attackers cannot poison the answers. Overkill for most small sites, worth it for some. How to decide.
Ports
What's reachable on your server, and what shouldn't be.
- 2026-06-08
WordPress REST API user enumeration: what it leaks, and the exact fix.
Your WordPress /wp-json/wp/v2/users endpoint lists everyone who has published. What attackers do with that list, and the snippet that closes it.
- 2026-04-09
RDP on the public internet: the single biggest ransomware vector for UK small businesses.
Remote Desktop on the public internet is the #1 ransomware vector for UK SMEs. Here's how to find out if you have one open, and the cheap way to close it.
Reputation
Whether your domain is flagged by Google Safe Browsing or sitting on a Spamhaus / SURBL list. Even clean sites end up on these, and it quietly costs you email deliverability.
- 2026-05-15
Google Safe Browsing: how it flags sites and how to clear yours.
Safe Browsing flags sites for malware or phishing, and clean sites get listed when a subdomain is hacked. How to check your domain and get delisted.
- 2026-06-21
DNS-based blocklists: the silent reason your emails land in spam.
Real-time blocklists decide whether your email lands in the inbox or in spam. How Spamhaus and the other big lists work, and how to get delisted.
Supply chain
Every third-party script your site loads is a supply-chain risk. Subresource Integrity, flagged CDNs, and what to do about both.
- 2026-05-11
Subresource Integrity: the third-party script defence most sites skip.
If you load scripts from a CDN, Subresource Integrity checks they have not been swapped. One attribute per script tag, and the exact syntax.
Privacy
Pre-consent trackers, cookie banners, the IAB TCF signal. The GDPR and ePrivacy basics a visitor or regulator would spot without opening DevTools.
- 2026-04-15
UK cookie consent: the ICO rule most sites ignore.
Most cookie banners on UK sites miss the ICO's consent-before-tracking rule. What the rule says and how to test your own banner.
Vulnerabilities
Known software vulnerabilities affecting your stack.
- 2026-04-09
What a passive security scan can and cannot prove about your site.
Vantyris scans your site from the outside, the way an attacker would. What that proves with confidence, and what it can only flag for you to confirm.
- 2026-07-14
What is a WAF, and when is it worth paying for one?
A web application firewall filters bad traffic before it reaches your site. What it does, and when a small business needs one before cheaper fixes.
- 2026-07-16
How Vantyris continuous monitoring works (without daily noise).
Enrol a verified target and Vantyris re-scans it on your schedule. You get an email only when something material changes, such as a new critical finding.
- 2026-07-18
Free vs paid website security scanners: what you actually get.
Free tools such as SSL Labs and MDN Observatory are useful. Where they stop, and when paying for scans earns its keep for a small business.
Want to scan your own site against everything above?
Vantyris runs the same checks the articles describe, then writes you a report you can hand to your web host. Free teaser, no signup. Verified scan from $10€10£10A$15¥1,500AED 40.
Run a free check →