NXT DEFENDBeta
Know your security posture. Prove it. Fix it. Watch it.
A defensive command center for the domains you own: DNS, email authentication, certificates and HTTPS headers — every result with the exact evidence, a plain-language fix, and a score you can audit.
- Ownership verified before any HTTPS request
- Evidence shown exactly as observed
- Daily monitoring with alerts
Overall score
- Open high
- 2
- Open medium
- 3
- Open low
- 3
- Certs ≤ 30 days
- 1
- Verified
- 2/3
- Monitored
- 2/3
- contoso-shop.example Verified▲ +72 low
- fabrikam-mail.example Unverified— no change2 high1 medium
- northwind-demo.example Verified— no change1 high1 medium
- No DMARC recordFix
fabrikam-mail.example · high · Email
- Ownership verification lost for tailspin-labs.exampleRe-verify
The verification record is gone, so HTTPS checks and monitoring stopped.
- Certificate for www.northwind-demo.example expires in 12 daysReview
northwind-demo.example · from Certificate Transparency logs
- Verify fabrikam-mail.example to unlock HTTPS and header checksVerify
Only public DNS and Certificate Transparency checks run until then.
Fail · highNo DMARC recordfabrikam-mail.example
Evidence
_dmarc.fabrikam-mail.example TXT (none)
What to do
Publish v=DMARC1; p=none; rua=mailto:… to start collecting reports, then move to p=quarantine or p=reject.
Fail · mediumSPF needs 12 DNS lookups (limit is 10)fabrikam-mail.example
Evidence
include:_spf.google.com include:mailgun.org include:sendgrid.net … (12 lookups)
What to do
Remove includes for services you no longer use, or flatten one of them.
Warning · mediumContent-Security-Policy allows unsafe-inlinenorthwind-demo.example
Evidence
content-security-policy: default-src 'self'; script-src 'self' 'unsafe-inline'
What to do
Move inline scripts to files and drop unsafe-inline, or use nonces.
Warning · highCertificate for www.northwind-demo.example expires in 12 daysnorthwind-demo.example
Evidence
Issuer R11 · not after 2026-10-15 09:12 UTC (from Certificate Transparency logs)
What to do
Check that automatic renewal is working for this host.
PassCAA records restrict certificate issuancenorthwind-demo.example
Evidence
northwind-demo.example CAA 0 issue "letsencrypt.org"
What to do
Nothing to do.
Checks
Four areas, checked the same way every time
Each check produces a result (pass, warning, failure or information), a severity, the record or header we saw, and what to do about it.
DNS
Public lookups through DNS-over-HTTPS.
- Domain resolves (A, AAAA, MX, NS)
- CAA records restrict certificate issuance
- DNSSEC validated
Email authentication
What stops someone sending mail as you.
- SPF policy, syntax and the 10-lookup limit
- DKIM keys for your selectors, with key size
- DMARC policy, subdomain policy, pct and reporting
- MTA-STS and TLS-RPT
HTTPS & headers
A few polite requests — verified hosts only.
- HTTPS reachable and HTTP redirects to HTTPS
- HSTS, Content-Security-Policy, clickjacking protection
- X-Content-Type-Options, Referrer- and Permissions-Policy
- Cookie flags (values are never recorded), security.txt
Certificates
From public Certificate Transparency logs.
- Certificates issued for your names
- Expiry warnings at 30, 14 and 7 days
- Never a TLS scan of your server
Findings
Evidence first, then what to do
No vague “risk detected”. You see the DNS record or response header exactly as observed, escaped and quoted, next to the change that fixes it.
A score you can audit
Each check is weighted by severity (high 4, medium 2, low 1). A pass earns its full weight, a warning 40% and a failure nothing; informational results don’t count. The asset score is the share of weight earned in its latest full check; the workspace score is the average of asset scores.
Fail · highNo DMARC recordfabrikam-mail.example
Evidence
_dmarc.fabrikam-mail.example TXT (none)
What to do
Publish v=DMARC1; p=none; rua=mailto:… to start collecting reports, then move to p=quarantine or p=reject.
Fail · mediumSPF needs 12 DNS lookups (limit is 10)fabrikam-mail.example
Evidence
include:_spf.google.com include:mailgun.org include:sendgrid.net … (12 lookups)
What to do
Remove includes for services you no longer use, or flatten one of them.
Warning · mediumContent-Security-Policy allows unsafe-inlinenorthwind-demo.example
Evidence
content-security-policy: default-src 'self'; script-src 'self' 'unsafe-inline'
What to do
Move inline scripts to files and drop unsafe-inline, or use nonces.
Warning · highCertificate for www.northwind-demo.example expires in 12 daysnorthwind-demo.example
Evidence
Issuer R11 · not after 2026-10-15 09:12 UTC (from Certificate Transparency logs)
What to do
Check that automatic renewal is working for this host.
PassCAA records restrict certificate issuancenorthwind-demo.example
Evidence
northwind-demo.example CAA 0 issue "letsencrypt.org"
What to do
Nothing to do.
Ownership
Verification before anything touches your servers
NXT DEFEND is built for domains you control. The order of operations is enforced by the product, not by a checkbox.
- 01
Add a domain
Tick that you own it or are authorized to test it. IP addresses and reserved names are refused.
fabrikam-mail.example - 02
Public checks run
DNS, email authentication and Certificate Transparency — nothing touches your servers.
dns · email · ct - 03
Prove ownership
A DNS TXT record (covers subdomains) or a well-known file (that host only).
nxt-defend-verification=… - 04
HTTPS checks unlock
Requests identify themselves as NXT-DEFEND-Check and go only to verified hosts.
NXT-DEFEND-Check/1.0 - 05
Re-verified weekly
If the record disappears, requests stop and monitoring turns off — you’re told why.
verification lost → stopped
Monitoring
Told when something changes — not every day it doesn’t
Monitored assets are re-checked about once a day. Alerts go to the workspace’s owners, admins and managers, in the app and by email.
- New high or medium findings
- Certificates expiring in 30, 14 and 7 days
- SPF or DMARC records changed or removed
- Ownership verification lost
- No DMARC recordFix
fabrikam-mail.example · high · Email
- Ownership verification lost for tailspin-labs.exampleRe-verify
The verification record is gone, so HTTPS checks and monitoring stopped.
- Certificate for www.northwind-demo.example expires in 12 daysReview
northwind-demo.example · from Certificate Transparency logs
- Verify fabrikam-mail.example to unlock HTTPS and header checksVerify
Only public DNS and Certificate Transparency checks run until then.
Toolbox
Password and hash tools that never upload a thing
Strength estimates, generators, hashes, HMAC and file checksums run in your browser. The breached-password check sends only the first 5 characters of a SHA-1 hash.
- 01
Your browser computes SHA-1 of the password.
5BAA6 1E4C9B93F3F0682250B6CF8331B7EE68FD8 - 02
Only the first 5 characters are sent; the range comes back padded.
GET …/range/5BAA6 - 03
Your browser looks for the rest of the hash in that list.
1E4C9B93…FD8 → found
Example values. Breach data from Have I Been Pwned (CC BY 4.0).
Strictly defensive
What NXT DEFEND will never do
No port or vulnerability scanning
No exploit attempts, brute force or fuzzing — ever.
No subdomain discovery
Only the hostnames you list are checked.
No IP scanning
IP addresses are stored for your records and never contacted.
Not a penetration test
A high score is not a guarantee of security or compliance.
Automated checks look at public DNS, Certificate Transparency logs and a few HTTPS responses. They can miss problems and don’t replace a professional security assessment or penetration test, and a high score is not a guarantee that a site is secure or compliant with any standard.
Plans
NXT DEFEND plans
Priced per workspace. Annual billing costs ten months instead of twelve.
See every limit and compare plans on the pricing page.
Ecosystem
Works well with
Same account, same workspace, no extra sign-up.