1 free scan. No account required.
Create a free Felixous account to save this report and run unlimited scans.
Vol. I · No. 1 — Greater Toronto Area, Canada — Thursday, October 1, 2026 — Managed IT & Cybersecurity
Website Vulnerability Scanner
2026-08-23, 8:27:32 p.m. · Felixous passive scanner (self-hosted, no third-party APIs)
1 free scan. No account required.
Create a free Felixous account to save this report and run unlimited scans.
The site does not tell browsers to always use HTTPS, so visitors can be downgraded to an unencrypted connection on public networks.
Fix: Add the header: Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
No v=DMARC1 TXT record exists at _dmarc.glxreno.com. Receivers have no instructions for handling mail that fails SPF/DKIM, and you get no visibility into spoofing.
Fix: Add a TXT record at _dmarc.glxreno.com: "v=DMARC1; p=quarantine; rua=mailto:[email protected]" as a starting point, then escalate to p=reject once reports confirm legitimate mail passes.
Without a Content Security Policy, the browser will run any script injected into the page, which makes cross-site scripting (XSS) attacks much easier.
Fix: Add a restrictive policy, e.g.: Content-Security-Policy: default-src 'self'; frame-ancestors 'none'; base-uri 'self'
The page can be embedded in an invisible frame on a malicious site, letting attackers trick visitors into clicking things they cannot see.
Fix: Add the header: X-Frame-Options: DENY (or SAMEORIGIN), or add frame-ancestors 'none' to your Content-Security-Policy.
None of the common selectors (google, selector1, selector2, default, mail, k1) answered at *._domainkey.glxreno.com. The domain may still sign mail with a custom selector, so this is not proof DKIM is absent — but no DKIM could be verified.
Fix: Enable DKIM signing in your mail provider and publish the TXT record it generates (e.g. google._domainkey for Google Workspace, selector1/selector2._domainkey for Microsoft 365).
Browsers may guess ("sniff") the type of downloaded files, which can turn an uploaded file into executable content.
Fix: Add the header: X-Content-Type-Options: nosniff
Without a Referrer-Policy, full URLs (which may contain sensitive query parameters) can leak to third-party sites.
Fix: Add the header: Referrer-Policy: strict-origin-when-cross-origin
No Permissions-Policy means any script on the page may request access to the camera, microphone, geolocation and other browser features.
Fix: Add the header: Permissions-Policy: camera=(), microphone=(), geolocation=()
The certificate is valid for another 70 day(s).
Fix: No action needed.
TLS 1.3 is the current best-practice protocol.
Fix: No action needed.
The server answered 403, so the path appears to exist but refuses anonymous access.
Fix: Confirm access controls stay in place; ideally return 404 for sensitive paths.
Our cybersecurity service hardens your site, then monitors it continuously so new exposures get caught before attackers find them.
Results are informational, not a guarantee of security. These are passive, read-only checks. A clean report does not prove a site is secure, and a finding may have compensating controls we cannot see. Terms
172.64.80.1 appears in the Spamhaus ZEN blocklist, which usually means spam or abuse was observed from this address. Email deliverability and visitor trust can be affected.
Fix: Check the listing at the blocklist's site, resolve the root cause (compromised account, open relay, shared hosting neighbour), then request delisting.
Unauthorized senders are marked but usually still delivered. Softfail is a reasonable transitional state but weaker than -all.
Fix: Once confident every legitimate sender is listed, tighten the record to end in -all.