The full audit

Every DNS and email check we run on your domain.

35 checks across 6 infrastructure categories, in under 60 seconds. Copy-paste fix guides included for every issue found.

35
security checks
6
infrastructure categories
<60s
to a full report
4
compliance frameworks

35-point advanced audit

Everything DNS security. One platform.

We analyze 35 critical security markers across 6 infrastructure categories, in under 60 seconds.

Email Authentication

4 checks

Core email security protocols and validation. Without these, your domain can be spoofed to send phishing emails that appear to come from you.

SPFDKIMDMARCPhishing protection
SPF Record
v=spf1 include:_spf.google.com ~all
DKIM Signature
selector=google, 2048-bit key
DMARC Policy
p=none, not enforced, spoofing possible
DMARC Reporting
RUA present, RUF missing

Compliance frameworks

Automated compliance checks for 4 frameworks.

Every scan maps to NIS2, GDPR, ISO 27001, and PCI-DSS. Know your compliance status before the auditor does.

NIS2 (EU Directive 2022/2555)

Network and Information Security Directive

Requirements6 checksPenaltiesUp to €10M or 2% of global turnover

Critical for

Essential EntitiesImportant EntitiesCritical Infrastructure
Check your compliance

We check:

Email authentication (SPF, DKIM, DMARC enforcement)
DNS integrity protection (DNSSEC)
Secure communication channels (MTA-STS)
Incident detection and monitoring
Regular security audits
Supply chain security measures

Detailed remediations

Step-by-step fix guides for every issue.

Every failing check comes with exact DNS records, provider-specific instructions, and a verification command.

DMARC Policy Not Enforced| domain can be spoofed for phishing
1
Understand Current State

Your DMARC record exists but policy is set to "none". No enforcement actions are taken on failed emails.

Current: v=DMARC1; p=none; rua=mailto:[email protected]
Estimated time: 5–15 min per step

What's in your report

Comprehensive analysis delivered in seconds.

Every audit generates a detailed security report with scores, issues, and fix guides.

Executive Summary

High-level security score, risk level, and critical issues at a glance.

  • Overall security score (0-100)
  • Risk level classification
  • Issue count by severity
  • Compliance status overview

Detailed Findings

Complete analysis of all 35 security checks with pass/fail status.

  • Email security results
  • DNS configuration analysis
  • Transport security validation
  • Performance metrics

Remediations

Step-by-step instructions for resolving each issue.

  • Detailed remediation steps
  • Technical implementation guides
  • Code examples and DNS records
  • Estimated fix time and difficulty

Premium Insights

Advanced security strategies and expert recommendations.

  • Industry best practices
  • Advanced configuration tips
  • Compliance strategies
  • Performance optimization

Compliance Reports

Detailed compliance analysis for 4 major frameworks.

  • NIS2 Directive assessment
  • GDPR compliance check
  • ISO 27001 controls
  • PCI-DSS requirements

Historical Tracking

Track security improvements over time.

  • Score trends
  • Issue resolution timeline
  • Compliance progress
  • Comparative analysis

See what ZeroHook finds on your domain.

Create a free account for a 6-check basic audit, or upgrade for the full 35-check depth. Copy-paste fix guides included for every issue found.