Until today, your dashboard showed one blended score per site — an average of everything we check under "security," including your SSL certificate, security headers, open ports, and mixed content, but also your domain's SPF, DMARC, and MX records and whether your mail server shows up on a public blacklist. Those are two different problems with two different fixes, and averaging them together meant a broken DMARC record could quietly drag down a score for a site whose actual website was perfectly healthy — or the other way around.

Why one score wasn't enough

Web security and email security are unrelated systems that happen to share a domain name. A misconfigured DMARC record doesn't make your site more vulnerable to XSS, and an expired SSL certificate doesn't make your mail server more likely to land on a blacklist. Blending them into a single number hid which one actually needed attention — so we split it.

What's in each rating

Every site on your dashboard now shows two ratings side by side:

  • Web — SSL, security headers, open ports, mixed content, dependency and vulnerability checks, rate limiting, server fingerprinting, plus your SEO and performance results.
  • Email — SPF/DMARC/MX configuration ("Correct Email") and whether your mail server's IP is listed on any of the major DNSBLs ("Email Blacklist").

What this means for you

Each rating gets its own grade and its own 0–100 score, computed straight from the same daily scan — nothing new to configure, and nothing scans differently. If you've only ever seen one number for a site, you may notice its Web and Email grades don't match; that's the point. A site can be an A on the web side and a C on email (or vice versa), and now you can tell which one needs attention without opening the full report.

Not yet tracking your site's Web and Email ratings? Start a free scan and see both the next time we run your daily check.