NVZ Score
A composite security rating for any domain — calculated from real DNS, HTTP headers, and certificate data. Scores range from 0 to 100.
Score Bands
What your NVZ Score means at a glance.
Excellent security posture. Most critical controls are in place including DMARC, HSTS, CSP, and a valid SSL certificate.
Solid foundations. Most headers are present but there may be gaps in email security or advanced policies.
Partial coverage. Key security headers or email controls are missing. Room for meaningful improvement.
Significant security gaps. Multiple critical headers and policies are absent. Immediate action recommended.
Scoring Breakdown
| Metric | If Present | If Missing | Category |
|---|---|---|---|
|
Content-Security-Policy
Restricts sources of scripts, styles, and media
|
+5 | −5 | Security Headers |
|
Strict-Transport-Security
Forces HTTPS connections (HSTS)
|
+5 | −5 | Security Headers |
|
X-Content-Type-Options
Prevents MIME-type sniffing attacks
|
+5 | −5 | Security Headers |
|
X-Frame-Options
Prevents clickjacking via iframes
|
+5 | −5 | Security Headers |
|
X-XSS-Protection
Legacy XSS filter (older browsers)
|
+4 | 0 | Security Headers |
|
Permissions-Policy
Controls browser feature access (camera, mic, etc.)
|
+5 | −5 | Security Headers |
|
Referrer-Policy
Controls referrer data sent in requests
|
+5 | −3 | Security Headers |
|
SSL Certificate (DV)
Valid Domain Validated certificate
|
+5 | — | Domain Trust |
|
DMARC Record
Email authentication & anti-spoofing policy
|
+15 | 0 | Email Security |
|
MTA-STS Policy
Enforces TLS for incoming email delivery
|
+10 | 0 | Email Security |
|
SMTP TLS Reporting
Reports TLS delivery failures to domain owner
|
+10 | 0 | Email Security |
|
Security.txt
Responsible disclosure contact file
|
+15 | 0 | Domain Trust |
|
Domain Age
Age of domain registration (WHOIS)
|
+15 +10 +5 | 0 | Domain Trust |
How We Collect Data
NVZS performs a fully passive scan — we never send login requests, modify DNS, or interact with your backend. Data is gathered from three sources: