CLOUD DEFEND

NXT DEFENDBeta

Know your security posture. Prove it. Fix it. Watch it.

A defensive command center for the domains you own: DNS, email authentication, certificates and HTTPS headers — every result with the exact evidence, a plain-language fix, and a score you can audit.

  • Ownership verified before any HTTPS request
  • Evidence shown exactly as observed
  • Daily monitoring with alerts

Overall score

Open high
2
Open medium
3
Open low
3
Certs ≤ 30 days
1
Verified
2/3
Monitored
2/3
  • contoso-shop.example Verified▲ +72 low
  • fabrikam-mail.example Unverified— no change2 high1 medium
  • northwind-demo.example Verified— no change1 high1 medium
  1. No DMARC record

    fabrikam-mail.example · high · Email

    Fix
  2. Ownership verification lost for tailspin-labs.example

    The verification record is gone, so HTTPS checks and monitoring stopped.

    Re-verify
  3. Certificate for www.northwind-demo.example expires in 12 days

    northwind-demo.example · from Certificate Transparency logs

    Review
  4. Verify fabrikam-mail.example to unlock HTTPS and header checks

    Only public DNS and Certificate Transparency checks run until then.

    Verify
  • Fail · highNo DMARC recordfabrikam-mail.example

    Evidence

    _dmarc.fabrikam-mail.example TXT (none)

    What to do

    Publish v=DMARC1; p=none; rua=mailto:… to start collecting reports, then move to p=quarantine or p=reject.

    Open fabrikam-mail.example

  • Fail · mediumSPF needs 12 DNS lookups (limit is 10)fabrikam-mail.example

    Evidence

    include:_spf.google.com include:mailgun.org include:sendgrid.net … (12 lookups)

    What to do

    Remove includes for services you no longer use, or flatten one of them.

    Open fabrikam-mail.example

  • Warning · mediumContent-Security-Policy allows unsafe-inlinenorthwind-demo.example

    Evidence

    content-security-policy: default-src 'self'; script-src 'self' 'unsafe-inline'

    What to do

    Move inline scripts to files and drop unsafe-inline, or use nonces.

    Open northwind-demo.example

  • Warning · highCertificate for www.northwind-demo.example expires in 12 daysnorthwind-demo.example

    Evidence

    Issuer R11 · not after 2026-10-15 09:12 UTC (from Certificate Transparency logs)

    What to do

    Check that automatic renewal is working for this host.

    Open northwind-demo.example

  • PassCAA records restrict certificate issuancenorthwind-demo.example

    Evidence

    northwind-demo.example CAA 0 issue "letsencrypt.org"

    What to do

    Nothing to do.

    Open northwind-demo.example

Preview · sample data

Checks

Four areas, checked the same way every time

Each check produces a result (pass, warning, failure or information), a severity, the record or header we saw, and what to do about it.

  • DNS

    Public lookups through DNS-over-HTTPS.

    • Domain resolves (A, AAAA, MX, NS)
    • CAA records restrict certificate issuance
    • DNSSEC validated
  • Email authentication

    What stops someone sending mail as you.

    • SPF policy, syntax and the 10-lookup limit
    • DKIM keys for your selectors, with key size
    • DMARC policy, subdomain policy, pct and reporting
    • MTA-STS and TLS-RPT
  • HTTPS & headers

    A few polite requests — verified hosts only.

    • HTTPS reachable and HTTP redirects to HTTPS
    • HSTS, Content-Security-Policy, clickjacking protection
    • X-Content-Type-Options, Referrer- and Permissions-Policy
    • Cookie flags (values are never recorded), security.txt
  • Certificates

    From public Certificate Transparency logs.

    • Certificates issued for your names
    • Expiry warnings at 30, 14 and 7 days
    • Never a TLS scan of your server

Findings

Evidence first, then what to do

No vague “risk detected”. You see the DNS record or response header exactly as observed, escaped and quoted, next to the change that fixes it.

A score you can audit

Each check is weighted by severity (high 4, medium 2, low 1). A pass earns its full weight, a warning 40% and a failure nothing; informational results don’t count. The asset score is the share of weight earned in its latest full check; the workspace score is the average of asset scores.

  • Fail · highNo DMARC recordfabrikam-mail.example

    Evidence

    _dmarc.fabrikam-mail.example TXT (none)

    What to do

    Publish v=DMARC1; p=none; rua=mailto:… to start collecting reports, then move to p=quarantine or p=reject.

    Open fabrikam-mail.example

  • Fail · mediumSPF needs 12 DNS lookups (limit is 10)fabrikam-mail.example

    Evidence

    include:_spf.google.com include:mailgun.org include:sendgrid.net … (12 lookups)

    What to do

    Remove includes for services you no longer use, or flatten one of them.

    Open fabrikam-mail.example

  • Warning · mediumContent-Security-Policy allows unsafe-inlinenorthwind-demo.example

    Evidence

    content-security-policy: default-src 'self'; script-src 'self' 'unsafe-inline'

    What to do

    Move inline scripts to files and drop unsafe-inline, or use nonces.

    Open northwind-demo.example

  • Warning · highCertificate for www.northwind-demo.example expires in 12 daysnorthwind-demo.example

    Evidence

    Issuer R11 · not after 2026-10-15 09:12 UTC (from Certificate Transparency logs)

    What to do

    Check that automatic renewal is working for this host.

    Open northwind-demo.example

  • PassCAA records restrict certificate issuancenorthwind-demo.example

    Evidence

    northwind-demo.example CAA 0 issue "letsencrypt.org"

    What to do

    Nothing to do.

    Open northwind-demo.example

Preview · sample data

Ownership

Verification before anything touches your servers

NXT DEFEND is built for domains you control. The order of operations is enforced by the product, not by a checkbox.

  1. 01

    Add a domain

    Tick that you own it or are authorized to test it. IP addresses and reserved names are refused.

    fabrikam-mail.example
  2. 02

    Public checks run

    DNS, email authentication and Certificate Transparency — nothing touches your servers.

    dns · email · ct
  3. 03

    Prove ownership

    A DNS TXT record (covers subdomains) or a well-known file (that host only).

    nxt-defend-verification=…
  4. 04

    HTTPS checks unlock

    Requests identify themselves as NXT-DEFEND-Check and go only to verified hosts.

    NXT-DEFEND-Check/1.0
  5. 05

    Re-verified weekly

    If the record disappears, requests stop and monitoring turns off — you’re told why.

    verification lost → stopped

Monitoring

Told when something changes — not every day it doesn’t

Monitored assets are re-checked about once a day. Alerts go to the workspace’s owners, admins and managers, in the app and by email.

  • New high or medium findings
  • Certificates expiring in 30, 14 and 7 days
  • SPF or DMARC records changed or removed
  • Ownership verification lost
  1. No DMARC record

    fabrikam-mail.example · high · Email

    Fix
  2. Ownership verification lost for tailspin-labs.example

    The verification record is gone, so HTTPS checks and monitoring stopped.

    Re-verify
  3. Certificate for www.northwind-demo.example expires in 12 days

    northwind-demo.example · from Certificate Transparency logs

    Review
  4. Verify fabrikam-mail.example to unlock HTTPS and header checks

    Only public DNS and Certificate Transparency checks run until then.

    Verify
Preview · sample data

Toolbox

Password and hash tools that never upload a thing

Strength estimates, generators, hashes, HMAC and file checksums run in your browser. The breached-password check sends only the first 5 characters of a SHA-1 hash.

  1. 01

    Your browser computes SHA-1 of the password.

    5BAA6 1E4C9B93F3F0682250B6CF8331B7EE68FD8
  2. 02

    Only the first 5 characters are sent; the range comes back padded.

    GET …/range/5BAA6
  3. 03

    Your browser looks for the rest of the hash in that list.

    1E4C9B93…FD8 → found

Example values. Breach data from Have I Been Pwned (CC BY 4.0).

Strictly defensive

What NXT DEFEND will never do

  • No port or vulnerability scanning

    No exploit attempts, brute force or fuzzing — ever.

  • No subdomain discovery

    Only the hostnames you list are checked.

  • No IP scanning

    IP addresses are stored for your records and never contacted.

  • Not a penetration test

    A high score is not a guarantee of security or compliance.

Automated checks look at public DNS, Certificate Transparency logs and a few HTTPS responses. They can miss problems and don’t replace a professional security assessment or penetration test, and a high score is not a guarantee that a site is secure or compliant with any standard.

Plans

NXT DEFEND plans

Priced per workspace. Annual billing costs ten months instead of twelve.

See every limit and compare plans on the pricing page.

Ecosystem

Works well with

Same account, same workspace, no extra sign-up.

↑↓ navigate↵ openEsc close