🛡️ Security Guides & Tools
SSL/TLS, security headers, DNSSEC, and practical security checks for websites, domains, and networks.
🔎 Search Security guides & tools…
Ctrl K
⭐ FEATURED
Featured Guide
Security
DNSSEC Basics
A complete beginner's guide to DNS Security Extensions — what DNSSEC protects against, how the chain of trust works, and how to check it.
Read the guide →Foundations
Security
What Is SSL/TLS?
SSL/TLS explained simply — how the handshake works, certificate types, SSL vs TLS, and how to check any domain's certificate history for free.
Security
What Is a DNS Leak? A Complete Beginner-to-Advanced Guide
A complete guide to what a DNS leak actually is, why it happens at the protocol level, how it differs from other privacy leaks, and how to spot one.
Security
DNS Privacy Explained: Who Sees Your Lookups and Why It Matters
A deep look at DNS as a privacy surface — who can observe your queries by default, what encrypted DNS actually changes, and what it doesn't.
SSL/TLS Certificates
Security
TLS/SSL Protocol & Certificate Types Guide
What actually changed in TLS 1.3, and the real differences between wildcard and SAN (multi-domain) SSL certificates.
Security
SSL Certificate Validation Levels: EV vs OV vs DV
What DV, OV, and EV SSL certificates actually verify, and how the certificate chain of trust is validated by browsers.
Security
Certificate Security & Trust Verification
How OCSP stapling checks certificate revocation in real time, and how Certificate Transparency logs catch fraudulent certificates.
Security
Decoding a CSR: Reading SAN & Subject Fields
How a PKCS#10 CSR is structured at the ASN.1 level, how to read openssl req -text output, and why SAN — not Common Name — actually matters.
Security
Verifying & Troubleshooting CSR Errors
How to verify a CSR's signature, confirm it matches a private key, decode common error messages, and a systematic troubleshooting checklist.
Security
X.509 Certificate Structure: Fields & SAN Extension
How an issued certificate is structured at the ASN.1 level — extensions, the criticality flag, and the SAN GeneralName types browsers check.
Security
Certificate Chains & PEM vs DER Encoding
How a certificate chain is verified link by link, why incomplete chains are the most common deployment error, and PEM vs DER explained.
Security
Root CA & Intermediate Certificates Explained
How root certificates earn trust, why intermediates exist as a working layer beneath them, and what happens when one is distrusted.
Security
Broken Certificate Chain: Errors & Fixes
How to read chain error messages from Chrome, Firefox, curl, and Java, and fix them on nginx, Apache, or IIS.
Security
SQL Injection Basics, Testing & Blind SQLi Explained
The three broad categories of SQL injection, and how blind SQLi extracts data one bit at a time without visible output.
Security
SQL Injection Prevention & Parameterized Queries
How parameterized queries eliminate SQL injection structurally, and why filtering alone always eventually fails.
🛠️ RELATED TOOLS
Security Tools
🔒
SSL Certificate Checker
Inspect a site's SSL/TLS certificate
📜
CSR Generator
Generate a CSR & private key in-browser
🔎
CSR Decoder
Decode a CSR's subject & SAN fields
📄
Certificate Decoder
Decode an issued certificate's fields
🔗
Certificate Chain Checker
Verify signature links in a certificate chain
🛡️
SQL Injection Checker
Check text for common SQL injection patterns
🛡️
Security Headers Checker
Check HTTP security header configuration
🛡️
DNSSEC Lookup
Verify DNSSEC signing on a domain
🔎
Website Security Scanner
Scan a site for common security issues
📋
HTTP Headers Checker
Inspect all HTTP response headers
🔑
Password Generator
Generate strong random passwords
📚 24 GUIDES
Security Guides, Organized by Path
Password Security
Security
Password Strength & Creation Guide
Why length beats complexity, the NIST guidelines that changed policy, and a step-by-step method for building strong passwords.
Security
Password Hashing vs Encryption Explained
The real difference between hashing and encryption, and why passwords must always be hashed, never encrypted.
Security
Common Password Attacks & Risks
Brute force, credential stuffing, password spraying, phishing and every major attack type explained with real defenses.
Advanced: DNSSEC Deep Dive
Security
DNSSEC Basics: A Complete Beginner's Guide
What DNSSEC is, the problem it solves, its history, and how the chain of trust actually works from the root down to your domain.
Security
DNSKEY Explained: Key Signing Keys, Zone Signing Keys & Rollover
How DNSKEY records work, why zones use separate Key Signing Keys and Zone Signing Keys, and how to roll them over safely.
Security
DS Record Explained: The Link in DNSSEC's Chain of Trust
What a DS record does, why it lives at the registrar rather than your DNS provider, and how to handle it correctly during key rollovers.
Security
RRSIG Explained: DNSSEC's Actual Cryptographic Signature
What an RRSIG record contains, how signing and re-signing work, and why signature expiration is DNSSEC's most common failure mode.
Security
NSEC vs NSEC3: Proving Non-Existence in DNSSEC
How NSEC and NSEC3 prove a DNS name doesn't exist, why NSEC3 was created to fix a zone enumeration weakness, and which to use.
Security
DNSSEC Validation Explained: How Resolvers Actually Verify Trust
How DNSSEC validation actually works on the resolver side, which resolvers validate by default, and what the AD flag really means.
Security
DNSSEC Errors: A Diagnostic Guide to Validation Failures
A symptom-first guide to diagnosing the most common DNSSEC validation failures, from expired signatures to broken key rollovers.
Certificate Authorization (CAA)
Security
CAA Records Explained: Certificate Authority Authorization
What CAA records are, their history from RFC 6844 to mandatory enforcement in 2017, and how they fit into the broader PKI ecosystem.
Security
CAA Best Practices: A Practical Guide to Certificate Authorization
Field-tested CAA record conventions covering CA authorization, wildcard restriction, iodef monitoring, and enterprise governance.
Security
DigiCert CAA Configuration: An Enterprise Guide
How to correctly authorize DigiCert through CAA records, including validation types, multi-brand considerations, and enterprise PKI governance.
Security
Let's Encrypt CAA Configuration: A Complete Guide
How to correctly configure CAA records to authorize Let's Encrypt, including wildcard issuance and advanced account-URI binding.
Security
How to Restrict SSL Certificate Issuers With CAA
How to design and implement a CAA-based SSL issuer restriction policy, from single-domain sites to enterprise multi-domain portfolios.
DNS Leak Prevention
Security
Browser DNS Leaks: Secure DNS, DoH Overrides & Extensions
How Chrome, Firefox, Edge, and Safari's own DNS settings can leak or override your VPN, and how browser extensions and WebRTC add further exposure.
Security
VPN DNS Leaks: Why They Happen and How to Fix Them
Why VPNs leak DNS queries even while showing 'Connected,' the specific client and OS configurations that cause it, and how to actually fix it per platform.
Security
How to Prevent DNS Leaks: A Complete Step-by-Step Guide
A complete, platform-by-platform action plan to prevent DNS leaks for good — VPN settings, OS configuration, browser lockdown, and ongoing verification.
Advanced Topics
Security
Security Headers Explained
HSTS, CSP, X-Frame-Options & more
Security
How CSP Works
Directives, nonces & rollout without breakage
Security
Complete Guide to HTTP Headers
Request & response headers explained
Security
SMTP TLS vs SSL: STARTTLS, Implicit TLS & the Real Difference
SSL is deprecated, TLS is its successor, and 'SSL' in mail settings almost always actually means TLS.
Security
Malware Signatures Explained: How Scanners Actually Detect Infections
What a malware signature is, how signature-based detection works, and its limits against new threats.
Security
Verified Mark Certificate (VMC): What It Is, Who Needs One & How to Get It
What a VMC actually proves, why Gmail and Apple Mail require one, the issuance process, realistic costs, and CMC as an alternative.
Security
Security Scan vs Penetration Test
What's the real difference?
Security
Interpreting Security Scan Scores
What a score does & doesn't tell you