NVZ Score

A composite security rating for any domain — calculated from real DNS, HTTP headers, and certificate data. Scores range from 0 to 100.

Score Bands

What your NVZ Score means at a glance.

85–100 Outstanding

Excellent security posture. Most critical controls are in place including DMARC, HSTS, CSP, and a valid SSL certificate.

70–84 Good

Solid foundations. Most headers are present but there may be gaps in email security or advanced policies.

50–69 Fair

Partial coverage. Key security headers or email controls are missing. Room for meaningful improvement.

0–49 Poor

Significant security gaps. Multiple critical headers and policies are absent. Immediate action recommended.

Scoring Breakdown

Metric If Present If Missing Category
Content-Security-Policy
Restricts sources of scripts, styles, and media
+5 −5 Security Headers
Strict-Transport-Security
Forces HTTPS connections (HSTS)
+5 −5 Security Headers
X-Content-Type-Options
Prevents MIME-type sniffing attacks
+5 −5 Security Headers
X-Frame-Options
Prevents clickjacking via iframes
+5 −5 Security Headers
X-XSS-Protection
Legacy XSS filter (older browsers)
+4 0 Security Headers
Permissions-Policy
Controls browser feature access (camera, mic, etc.)
+5 −5 Security Headers
Referrer-Policy
Controls referrer data sent in requests
+5 −3 Security Headers
SSL Certificate (DV)
Valid Domain Validated certificate
+5 Domain Trust
DMARC Record
Email authentication & anti-spoofing policy
+15 0 Email Security
MTA-STS Policy
Enforces TLS for incoming email delivery
+10 0 Email Security
SMTP TLS Reporting
Reports TLS delivery failures to domain owner
+10 0 Email Security
Security.txt
Responsible disclosure contact file
+15 0 Domain Trust
Domain Age
Age of domain registration (WHOIS)
+15 +10 +5 0 Domain Trust

How We Collect Data

NVZS performs a fully passive scan — we never send login requests, modify DNS, or interact with your backend. Data is gathered from three sources:

HTTP Headers
Security headers fetched from a live HTTP request to the domain's homepage.
DNS Records
DMARC, MTA-STS, and SMTP TLS policies resolved via public DNS.
WHOIS / SSL
Registration date from WHOIS and certificate details from the TLS handshake.

Frequently Asked Questions

Yes. The scoring breakdown table above shows exactly which controls earn or cost points. The highest-impact improvements are adding a DMARC record (+15), adding a security.txt file (+15), and enabling SMTP TLS reporting (+10) and MTA-STS (+10). On the HTTP side, ensure Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Permissions-Policy, and Referrer-Policy headers are all present.

The score is recalculated each time a domain is analyzed. If the domain has been scanned before, NVZS will serve the cached result. To force a fresh scan, use the "Re-test" option on the result page. Automated rescans are not currently scheduled, so scores reflect the state of the domain at the time of the last lookup.

Most domains score lower than expected because security headers are opt-in — they are not set by default by web servers or hosting platforms. A missing Content-Security-Policy costs −5 points, and a missing Permissions-Policy costs another −5. Combined, these seven header checks can swing the score by up to 38 points. Check the full result page for your domain to see exactly which items are missing.

The NVZ Score measures the presence of security policies and controls that are publicly observable. It is a useful baseline indicator but is not a penetration test or a guarantee of security. A high score means your domain has implemented common security best practices; it does not account for application-level vulnerabilities, server configuration details, or internal access controls.

Ready to check your domain?

Get your NVZ Score in seconds — no account required.

Analyze a Domain