Back to scanner
Scoring methodology

How the score is calculated

No black box. Every check, every data source, every point — explained openly so you know exactly what you're looking at and where it comes from.

We only read public records.

CyberRate doesn't access your systems, your email, or anything behind a login. Every check on this page reads information that's already publicly visible on the internet — the same records anyone can look up for free. We organize them into a report and tell you what they mean. We link to the original sources below so you can verify every finding yourself.

The seven checks

What we check, why it matters, and where the data comes from

Your score starts at 100. Each of these seven checks can subtract up to its maximum if it fails — the more directly a gap can be exploited, the more it costs. Checks we can't evaluate from the outside don't affect your score either way.

30points

Email impersonation protection (DMARC)

We check whether your domain has a DMARC policy published in public DNS. DMARC tells receiving mail servers what to do when someone sends email pretending to be from your domain. Without it, anyone on the internet can send an email that looks like it came from your organization — your executive director, your finance team, your board. This is the exact mechanism used in wire fraud and vendor impersonation scams. It's weighted highest because it's the most directly exploitable gap we can detect from the outside.

Public DNS record Verify yourself at mxtoolbox.com
15points

Email sender verification (SPF)

SPF is a DNS record that lists which mail servers are authorized to send email on behalf of your domain. Without it, spoofed emails from your domain are more likely to reach inboxes undetected. SPF works alongside DMARC — both records are required for complete email authentication. SPF alone without DMARC provides partial protection only.

Public DNS record Verify yourself at mxtoolbox.com
10points

Email signing (DKIM)

DKIM adds a cryptographic signature to outgoing emails. Receiving servers use it to verify the message was sent by an authorized source and wasn't altered in transit. It's the third layer of the email authentication stack alongside SPF and DMARC. All three work together — a gap in any one weakens the others.

Public DNS record Verify yourself at mxtoolbox.com
30points

Leaked credentials (dark web)

We query DeHashed — a publicly accessible breach intelligence database — for email addresses associated with your domain that have appeared in known data breaches. The risk is password reuse: if someone on your team uses the same password at work that was stolen in a breach somewhere else, an attacker may already have it. Score impact scales with how many accounts are exposed. We show you a count. The full account list is included in your emailed report.

DeHashed breach database Verify yourself at dehashed.com
10points

Website encryption (HTTPS)

We check whether your website has a valid SSL/TLS certificate and serves all traffic over HTTPS. An unencrypted site exposes visitor data in transit and signals to browsers — and attackers — that basic security hygiene is not in place. Modern browsers actively warn visitors when a site is unencrypted.

Public SSL certificate Verify yourself at ssllabs.com
10points

Website security headers

We check for HTTP security headers in your site's public responses — specifically Content-Security-Policy, X-Frame-Options, and related settings. These protect visitors from common web attacks like clickjacking and cross-site scripting. Missing headers are one of the most common and easiest-to-fix gaps we find.

Public HTTP response Verify yourself at securityheaders.com
5points

Spam and phishing filter

We read your public MX records to identify your mail provider and determine whether spam and phishing filtering is active. Organizations using Microsoft 365 or Google Workspace with default settings pass this check. Filtering reduces the likelihood that malicious emails reach your team in the first place.

Public DNS MX record Verify yourself at mxtoolbox.com
Starting score (before deductions) 100 points
Data sources

Where every finding comes from

Every check uses publicly accessible data. Nothing in your CyberRate report requires access to your systems. The links below let you run the same checks yourself for free.

CheckData sourceVerify it yourself
DMARCPublic DNS recordsmxtoolbox.com/dmarc
SPFPublic DNS recordsmxtoolbox.com/spf
DKIMPublic DNS recordsmxtoolbox.com/dkim
Leaked credentialsDeHashed breach databasedehashed.com
Website encryptionPublic SSL certificatessllabs.com
Security headersPublic HTTP responsesecurityheaders.com
Spam filterPublic DNS MX recordsmxtoolbox.com/mx
Leaked credentials — detailed scoring

How the leaked logins check works

When we find email addresses from your domain in breach databases, it means those credentials were captured in a data breach somewhere — LinkedIn, Adobe, Dropbox, or thousands of other sites. The direct risk is password reuse. If an employee uses the same password at work that was stolen in a breach elsewhere, an attacker already has it. Score impact scales with volume.

Accounts foundScore impactPoints lostResult
0 accountsNo penaltyPassed
1–3 accountsModerate−10 ptsWarning
4–9 accountsSignificant−20 ptsFailed
10+ accountsHeavy−30 ptsFailed
UnknownNo penaltyUnknown
What this check can't see: If your team uses multi-factor authentication, a password manager, or forced password resets after known breaches, your actual risk may be lower than this finding suggests. We can't detect those mitigations from the outside. That's part of what the free walkthrough covers — confirming whether your current setup makes these credentials exploitable or already neutralized.
Score override rule

The one rule that overrides everything else

A high average score can mask a single critical gap. CyberRate applies one hard override rule to prevent a passing score from obscuring a serious exposure.

Hard cap

DMARC failure caps your score at 59 (At Risk)

If your domain has no DMARC record, your score cannot exceed 59 — regardless of how well every other check performs. A missing DMARC record means anyone on the internet can send email impersonating your organization right now. No other passing check offsets that risk. One open door is all it takes.

This rule exists because security risk doesn't average out. A business with strong website encryption and no email impersonation protection is still one spoofed invoice away from a wire fraud loss.

Score bands

What your score means

Scores map to four named bands. The band reflects the severity and combination of gaps found — not just the raw number.

80–100
A
Fortified
Strong external posture. No critical gaps detected from publicly available data.
60–79
B
Solid
Minor gaps present. Low immediate risk but worth attention before they compound.
40–59
C
At Risk
Multiple exploitable gaps. Professional addressing recommended.
0–39
F
Exposed
Critical exposure. Immediate action needed. At least one severe gap is present.
Honest limitations

What this score doesn't measure

CyberRate is an external scan — we read what's publicly visible. Your score does not reflect what's happening inside your organization. A business can score well on all six external checks and still have serious internal gaps. These are things no external tool can see:

🔐

Multi-factor authentication

Whether MFA is enforced across accounts and systems.

💻

Endpoint protection

Antivirus, EDR, or device management on your team's computers.

🎓

Security awareness training

Whether your team can recognize phishing and social engineering.

💾

Backup and recovery

Whether your data is backed up and recoverable after a ransomware attack.

🌐

Internal network security

Firewall configuration, network segmentation, access controls.

🔑

Password hygiene

Whether your team uses unique passwords or a password manager.

👤

Offboarding controls

Whether departed employees still have access to your systems.

💳

Wire transfer controls

Whether your team has a verification process before moving money.

A score of 85 with no MFA and no offboarding process is still a serious exposure — the score just can't see it. That's exactly what the free 30-minute review is for.

Your privacy

Why we ask for your email

We ask for your email address at the end of the scan to send you the full report — including the complete list of any breached accounts found and the plain-English fix for each finding. That's the only reason.

  • We send your report to the address you provide. That's what you asked for.
  • We don't sell your email address. Ever.
  • We don't add you to marketing lists without your explicit opt-in.
  • We don't share your email with third parties.
  • The domain you scanned and your email are stored only to deliver your report and, if you opt in, to alert you when new breaches affect your domain.
  • You can ask us to delete your data at any time by emailing us directly.

We're a local IT company in Bloomington. Our business runs on trust and referrals. Abusing your email address would be bad for our business and bad for our reputation. We have no interest in doing it.

Ready to see your score?

Enter your domain and get your CyberRate report in under two minutes. No software. No access to your systems. Just your public records, organized and explained.

Get my CyberRate →