A real A-Grade Playbook, shown in full. This is exactly what you get.
The exact artifact, built by the same generator behind every Playbook: here run on example.com so you can see the whole thing: each fix, the precise record to add, where to add it, and the safe order to apply it. Yours is built the same way, from your own domain’s findings.
defaults.exposed scores A+. Scan us and check.
Scan your domain →Get yours free until 31 October
Defaults.Exposed
A-Grade Playbook · example.com
A-Grade Playbook

Your route to an A, one safe step at a time

example.com
D
Today · 65/100
→
A
Your target
15 of 23 checks already pass.
8 steps stand between you and an A. Each one below is ordered by risk, the safe, no-downside wins come first, and anything that can touch your mail flow comes last and clearly flagged.
Measured by the same engine that graded 316,600,902 domains in the Defaults.Exposed census · scanned 26 September 2026. Only 0.2% of .com domains reach an A.
Every step ends with a one-click re-scan so you can watch your grade move.
Defaults.Exposed
A-Grade Playbook · example.com
Step 1 of 8

Stop your site being framed (clickjacking)

No-risk change Does not affect mail
1The issue

A one-line instruction that tells browsers not to let other websites secretly load your site inside their own. Without it, a scammer can hide your real, logged-in pages behind a fake page and trick your customers into clicking things they never meant to: approving a payment, changing a password, granting access.

2What this means for your business

A fraudster can invisibly wrap your live website inside a fake one and steal money or account access from your logged-in customers, and to the customer it looks like your site did it. The fix is free and takes a developer about 15 minutes; leaving it off is a known gap that both criminals and cautious buyers can spot in seconds.

3What this means for your customers
  • A scammer hides your real login or payment screen behind a harmless-looking page and tricks a customer into 'confirming' a transfer or a setting change without realising it. The customer blames you rather than the attacker.
  • Your logged-in account area gets loaded invisibly on top of a 'You've won, click to claim' page; the click approves a change on the customer's account, and the customer calls your support line to complain.
4You're not alone

84.7% of .com domains have this exact gap. Only 15.3% have it in place.

5Your current setting
What we found on example.com
No X-Frame-Options header or CSP frame-ancestors directive found.
xFrameOptions = not set
cspFrameAncestors = not set
6The fix

WhereYour web server / CDN response headers

Add exactly this
X-Frame-Options: SAMEORIGIN (its own header, if you'd rather use CSP, add frame-ancestors 'self' to the Content-Security-Policy step instead of setting a second CSP header)

If you need to undo itDelete the header. If your site is embedded elsewhere on purpose, list those origins instead of self.

7Done looks like
curl -sI https://example.com | grep -i x-frame-options
x-frame-options: SAMEORIGIN
8Verify it worked

Re-check, the frame/clickjacking check passes.

Re-scan example.com →

Watch this check turn green.

Defaults.Exposed
A-Grade Playbook · example.com
Step 2 of 8

Add the MIME-sniffing header

No-risk change Does not affect mail
1The issue

A one-line header that stops browsers from guessing what a file is. Without it, a file someone uploads to your site, or a file on your own pages, can be mis-read by the browser and run as code, which is exactly how some attacks turn a harmless-looking upload into a way to steal your customers' sessions.

2What this means for your business

Missing this header is a clear, scannable sign that the basics aren't in place. On its own it rarely takes a site down, but combined with a file-upload form or user-generated content it opens a path for an attacker to run malicious code in your visitors' browsers to hijack logged-in sessions or steal card-entry and login details. That can turn into a data breach. It is one of the cheapest fixes in security: one line, free, about five minutes.

3What this means for your customers
  • Any page where customers or staff can upload files (avatars, documents, support attachments, listing photos) becomes a possible launch-pad for browser-side attacks.
  • An attacker can disguise malicious code as an image or text file and have the visitor's browser run it, stealing their logged-in session on your site.
4You're not alone

82.2% of .com domains have this exact gap. Only 17.8% have it in place.

5Your current setting
What we found on example.com
No X-Content-Type-Options header found.
xContentTypeOptions = not set
expectedValue = nosniff
6The fix

WhereYour web server / CDN response headers (Cloudflare: Rules → Transform Rules → Modify Response Header)

Add exactly this
X-Content-Type-Options: nosniff

If you need to undo itDelete the header rule. Nothing depends on it.

7Done looks like
curl -sI https://example.com | grep -i x-content-type-options
x-content-type-options: nosniff
8Verify it worked

Re-check, the x-content-type-options check flips to pass.

Re-scan example.com →

Watch this check turn green.

Defaults.Exposed
A-Grade Playbook · example.com
Step 3 of 8

Add a Referrer-Policy header

No-risk change Does not affect mail
1The issue

A Referrer-Policy is a one-line instruction your website hands to every visitor's browser, controlling how much of your web address travels with them when they click a link to another site. Without it, the full address of whatever page they were on (search terms, account numbers, reset links, internal page paths and all) is handed to the next site they land on, including advertisers, analytics firms, and anywhere else a link points.

2What this means for your business

Every time a visitor clicks an outbound link, ad, or shared resource, their browser can hand the full address of your page to the destination, and if your addresses carry search queries, customer IDs, order numbers, or one-time links, you are leaking customer data to third parties you do not control. Regulators treat that as a data-protection problem, and it breaks your own privacy promise. It is also a graded gap that a client's security team will flag during due diligence.

3What this means for your customers
  • A customer fills in a form or runs a search, then clicks an outbound link or ad, and the page address, complete with what they typed, is handed straight to an advertiser or analytics firm you never meant to share it with.
  • Password-reset and account-confirmation links sometimes carry a secret token in the web address; without this header, clicking any link on that page can pass the whole address, token included, to an outside site.
4You're not alone

92.1% of .com domains have this exact gap. Only 7.9% have it in place.

5Your current setting
What we found on example.com
No Referrer-Policy header found: visitor URLs may leak to third parties.
referrerPolicy = not set
isPermissive = false
6The fix

WhereYour web server / CDN response headers

Add exactly this
Referrer-Policy: strict-origin-when-cross-origin

If you need to undo itDelete the header rule.

7Done looks like
curl -sI https://example.com | grep -i referrer-policy
referrer-policy: strict-origin-when-cross-origin
8Verify it worked

Re-check, referrer-policy passes.

Re-scan example.com →

Watch this check turn green.

Defaults.Exposed
A-Grade Playbook · example.com
Step 4 of 8

Turn on HSTS (force HTTPS)

Low risk Does not affect mail
1The issue

HSTS is a one-line instruction your website gives every browser: 'always come back to me over the secure, encrypted connection, never the insecure one.' Without it, your padlock can be stripped away on shared WiFi, and the very first visit to your site is exposed.

2What this means for your business

Having HTTPS (the padlock) is not the same as enforcing it. Without HSTS, an attacker on the same WiFi as your customer can silently downgrade the connection to plain, unencrypted HTTP, capturing logins, card details and form data. Your SSL certificate, which you may be paying for, is bypassed. The fix is free and takes about 15 minutes for whoever runs your site.

3What this means for your customers
  • Customers on cafe, hotel, airport or conference WiFi can have their connection to your site downgraded and their data read, with no warning on their screen.
  • You paid for HTTPS and have the padlock, but without HSTS attackers can simply route around it; the certificate gives a false sense of safety.
4You're not alone

78.9% of .com domains have this exact gap. Only 21.1% have it in place.

5Your current setting
What we found on example.com
No Strict-Transport-Security header found.
hstsHeader = not set
6The fix

WhereYour web server / CDN response headers

Add exactly this
Strict-Transport-Security: max-age=31536000; includeSubDomains
Watch outOnly enable includeSubDomains once EVERY subdomain serves HTTPS, otherwise a plain-HTTP subdomain becomes unreachable. Start without it if unsure, add it later. Do NOT add `preload` until you are certain.

If you need to undo itLower max-age to 0 and wait out the old value before removing.

7Done looks like
curl -sI https://example.com | grep -i strict-transport
strict-transport-security: max-age=31536000; includeSubDomains
8Verify it worked

Re-check, hsts-header passes.

Re-scan example.com →

Watch this check turn green.

Defaults.Exposed
A-Grade Playbook · example.com
Step 5 of 8

Lock down who can issue your certificates (CAA)

Low risk Does not affect mail
1The issue

A CAA record is a short instruction in your domain settings that names which certificate companies are allowed to issue the 'padlock' security certificate for your website. With it switched on, no other company can create a valid certificate in your name.

2What this means for your business

Without a CAA record, almost any of the hundreds of certificate companies worldwide can issue a genuine, fully-trusted padlock certificate for your domain, letting a scammer run a padlocked copy of your site to harvest your customers' logins and card details, with nothing on screen to warn them.

3What this means for your customers
  • A scammer obtains a real certificate for a copy of your site, so the copy shows the green padlock and HTTPS. Your customers get no warning when they type in their passwords and card numbers, and the chargebacks come back to you.
  • Your customers get phished through a pixel-perfect look-alike of your login page; the fallout (refunds, support load, reputation damage) lands on your brand even though your real site was never touched.
4You're not alone

98.6% of .com domains have this exact gap. Only 1.4% have it in place.

5Your current setting
What we found on example.com
No CAA records found: any Certificate Authority can issue certificates for this domain.
dnsQuery = dig CAA example.com
caaRecords = no CAA records found
6The fix

WhereYour DNS host, add CAA records on example.com

Add exactly this
example.com. CAA 0 issue "letsencrypt.org" example.com. CAA 0 issue "pki.goog" example.com. CAA 0 iodef "mailto:security@example.com"
Watch outList EVERY CA that legitimately issues for you, including the one your CDN rotates through. Omit one and your next cert renewal fails silently weeks from now. Check your current cert issuer before publishing.

If you need to undo itDelete the CAA records (prior state was "any CA may issue").

7Done looks like
dig CAA example.com +short
0 issue "letsencrypt.org"
0 issue "pki.goog"
0 iodef "mailto:security@example.com"
8Verify it worked

dig CAA example.com +short shows your records → re-check.

Re-scan example.com →

Watch this check turn green.

Defaults.Exposed
A-Grade Playbook · example.com
Step 6 of 8

HTTP to HTTPS Redirect

Medium risk Does not affect mail
1The issue

HTTPS is the padlock in the browser bar. It encrypts everything that travels between your website and your customers so it can't be read or tampered with in transit. The forced-secure redirect makes sure visitors land on that encrypted version automatically, even when they type your address without 'https://'.

2What this means for your business

Without HTTPS, every password, card number and message a customer sends you crosses the internet as readable text, and Chrome, Edge, Safari and Firefox all stamp your site 'Not secure' for every visitor before they read a word. Without the redirect, even sites that have a certificate leave the very first visit unprotected. Both are free to fix in minutes.

3What this means for your customers
  • A first-time visitor sees a big 'Not secure' warning the moment your page loads. Most assume the site is fake, broken or unsafe and leave for a competitor.
  • A customer enters their card details or logs in over an unencrypted connection from a café, hotel or airport. Someone on the same WiFi reads it in plain text and uses it for fraudulent charges.
4Your current setting
What we found on example.com
HTTP requests are not redirected to HTTPS.
redirectsToHttps = false
httpUrl = http://example.com/
httpsUrl = https://example.com/
5The fix

WhereAdd a redirect from HTTP to HTTPS: Nginx: server { listen 80; server_name example.com; return 301 https://$host$request_uri; } Apache (.htaccess): RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] Cloudflare: SSL/TLS > Edge Certificates > Always Use HTTPS = On IIS: Install URL Rewrite module and add HTTP to HTTPS redirect rule

6Verify it worked

Re-check http-to-https-redirect after applying the fix.

Re-scan example.com →

Watch this check turn green.

Defaults.Exposed
A-Grade Playbook · example.com
Step 7 of 8

Publish a Content-Security-Policy

Medium risk Does not affect mail
1The issue

A Content Security Policy is a safety rule your website hands to every visitor's browser, telling it exactly which code is allowed to run. Without one, if anything malicious ever lands on a page (through a comment box, a hacked plugin, or a third-party script) the browser will run it freely, including code that skims your customers' card numbers and passwords as they type, with the padlock still showing.

2What this means for your business

If your site is ever tampered with, malicious code can read your customers' payment-card and login details straight off your own checkout while everything looks completely normal, leaving you with chargebacks, fraud claims, a reportable data breach, and a check failure that larger clients' security teams use to stall or kill a deal.

3What this means for your customers
  • Hidden code slips into one of your pages and copies every card number and password your customers enter at checkout, sending it to an attacker while your site looks completely normal. You only find out when the fraud complaints arrive.
  • A scammer plants a fake 'pay here' form on your real website that captures payments into their own account; customers think they paid you and demand their money back when the goods never come.
4You're not alone

89.9% of .com domains have this exact gap. Only 10.1% have it in place.

5Your current setting
What we found on example.com
No Content-Security-Policy header found.
cspHeader = not set
6The fix

WhereYour web server / CDN response headers

Add exactly this
Content-Security-Policy: default-src 'self'; img-src 'self' data:; style-src 'self'; script-src 'self'; frame-ancestors 'self'
Watch outA strict CSP can break inline scripts/styles and third-party widgets. Deploy first as Content-Security-Policy-Report-Only, watch for violations for a few days, then enforce.

If you need to undo itSwitch back to -Report-Only, or remove the header.

7Done looks like
curl -sI https://example.com | grep -i content-security-policy
content-security-policy: default-src 'self'; ...; frame-ancestors 'self'
8Verify it worked

Re-check, csp-header passes (report-only still counts as present; tighten toward enforce).

Re-scan example.com →

Watch this check turn green.

Defaults.Exposed
A-Grade Playbook · example.com
Step 8 of 8

DMARC Aggregate Reporting

Medium risk Does not affect mail
1The issue

DMARC can ask the world's mail providers to send you a regular summary of every message they received claiming to come from your domain: which servers sent it, and whether it passed SPF and DKIM. That request is the rua= tag in your DMARC record, and your record does not include it, so no reports are sent to you.

2What this means for your business

You cannot see who is sending email as your business. If a legitimate tool you rely on (an invoicing system, a newsletter platform, a new email provider) starts failing authentication, receivers can quarantine or reject its mail under your policy and nothing tells you. The same blind spot hides anyone trying to impersonate you.

3What this means for your customers
  • Your accounts team moves invoicing to a new platform that was never set up to sign as your domain. Receivers apply your DMARC policy to the invoices, customers never see them, and nobody can tell why payments slowed.
  • Someone starts sending email in your name from servers you have never used. Aggregate reports would list those servers from the first day; without them, you hear about it when a customer asks about an email you never sent.
4You're not alone

90.2% of .com domains have this exact gap. Only 9.8% have it in place.

5Your current setting
What we found on example.com
No rua= tag in DMARC record: no aggregate reports configured.
dnsQuery = dig TXT _dmarc.example.com
dmarcRecord = v=DMARC1;p=reject;sp=reject;adkim=s;aspf=s
ruaTag = not set
6The fix

WhereAdd a rua= tag to your existing DMARC record. Update the TXT record at _dmarc.example.com to include: rua=mailto:dmarc@example.com Full record example: v=DMARC1; p=reject; rua=mailto:dmarc@example.com Alternatively, use a free DMARC reporting service like dmarcian.com or postmarkapp.com/dmarc for easier report analysis.

7Verify it worked

Re-check dmarc-reporting after applying the fix.

Re-scan example.com →

Watch this check turn green.

  Defaults.Exposed · A-Grade Playbook for example.com · verify anytime at defaults.exposed