Atlassian
Good security posture with minor improvements possible. Strong in: dns, tls, headers, files, general.
The CSP includes 'unsafe-inline' or 'unsafe-eval' which weakens protection.
Recommendation: Remove unsafe directives and use nonces or hashes instead.
No CAA records found. CAA records specify which CAs can issue certificates.
Recommendation: Add CAA records to restrict certificate issuance to trusted CAs.
No Referrer-Policy header found.
Recommendation: Add a Referrer-Policy header (e.g., strict-origin-when-cross-origin).
No Permissions-Policy header found.
Recommendation: Add a Permissions-Policy header to control browser features.
SPF, DMARC, and DKIM are all configured for this domain.
HSTS is not applied to subdomains.
Recommendation: Consider adding includeSubDomains to HSTS if applicable.
Valid certificate, HSTS enabled, and TLS 1.3 supported.
Essential security headers (CSP, X-Frame-Options, X-Content-Type-Options) are configured.
No robots.txt file was found at the root.
Recommendation: Consider adding a robots.txt file to control crawler behavior.
A security.txt file exists, providing security contact information.