Server Security Guide

Server Security Guide for Kicksecure, Linux, and Kicksecure Hardening
Documentation for this is incomplete. Contributions are happily considered! See this for potential alternatives.
Contents
User Account Password Security
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#User_Account_Password_Security
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Server_Security_Guide#User_Account_Password_Security|User Account Password Security]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[User Account Password Security](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#User_Account_Password_Security)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[User Account Password Security](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#User_Account_Password_Security)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#User_Account_Password_Security]User Account Password Security[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
An adversary might connect a keyboard to a server and attempt to login into a virtual console. See also Virtual Consoles Usage Documentation and Protection against Physical Attacks, Virtual Consoles.
The user should set a password for account user
. If using user-sysmaint-split, the user should also set a password for account sysmaint
.
If logging in passwordless over SSH using public key authentication, the user might be tempted to Locking a Password. However, then recovery using a virtual console over a KVM switch (such as PiKVM) will be no longer possible.
Confidential Computing
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Confidential_Computing
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Server_Security_Guide#Confidential_Computing|Confidential Computing]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Confidential Computing](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Confidential_Computing)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Confidential Computing](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Confidential_Computing)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Confidential_Computing]Confidential Computing[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Confidential computing is an advanced security technology that protects data while it's in use, complementing existing protections for data at rest and in transit. The goal is to isolate sensitive data from unauthorized access, even from the cloud provider or system administrators.Confidential Computing (developers)
To the best of the author's knowledge, reasonably secure confidential computing is not currently achievable with Freedom Software. Technical details are available on the wiki pages Confidential Computing (developers) and Verified Boot.
E-Mail Delivery
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#E-Mail_Delivery
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Server_Security_Guide#E-Mail_Delivery|E-Mail Delivery]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[E-Mail Delivery](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#E-Mail_Delivery)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[E-Mail Delivery](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#E-Mail_Delivery)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#E-Mail_Delivery]E-Mail Delivery[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
DMARC Strict Alignment
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#DMARC_Strict_Alignment
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Server_Security_Guide#DMARC_Strict_Alignment|DMARC Strict Alignment]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[DMARC Strict Alignment](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#DMARC_Strict_Alignment)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[DMARC Strict Alignment](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#DMARC_Strict_Alignment)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#DMARC_Strict_Alignment]DMARC Strict Alignment[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Consider using DMARC strict alignment:
aspf=s;
adkim=s
- relaxed alignment
aspf=r;
/adkim=r
might lead to spammers sending e-mails impersonating the domain name and DMARC passing anyhow. - Illustrative examples on DMARC Strict Alignment
Tools
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Tools
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Server_Security_Guide#Tools|Tools]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Tools](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Tools)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Tools](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Tools)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Tools]Tools[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
- https://www.dmarcanalyzer.com/dmarc/dmarc-record-check/
- https://report-uri.com/account/reports/dmarc/
- https://www.mailhardener.com/dashboard/dmarc-reports
- https://www.mailhardener.com/tools/dkim-validator
- https://tools.socketlabs.com/
- SPF/DKIM/DMARC/DomainKey/RBL Online Test
- https://github.com/6point6/dmarc_checker
DKIM Header Injection Attack
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#DKIM_Header_Injection_Attack
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Server_Security_Guide#DKIM_Header_Injection_Attack|DKIM Header Injection Attack]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[DKIM Header Injection Attack](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#DKIM_Header_Injection_Attack)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[DKIM Header Injection Attack](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#DKIM_Header_Injection_Attack)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#DKIM_Header_Injection_Attack]DKIM Header Injection Attack[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Introduction:
- https://prog.world/dkim-replay-attack-on-gmail/
- https://utcc.utoronto.ca/~cks/space/blog/spam/DKIMSpamReplayAttack
- https://wordtothewise.com/2014/05/dkim-injected-headers/
- https://www.zdnet.com/article/dkim-useless-or-just-disappointing/
Mitigation:
- https://halon.io/blog/the-dkim-replay-attack-and-how-to-mitigate
- https://noxxi.de/research/breaking-dkim-on-purpose-and-by-chance.html
- https://proton.me/blog/dkim-replay-attack-breakdown
- https://security.stackexchange.com/questions/265408/how-many-times-need-e-mail-headers-be-signed-with-dkim-to-mitigate-dkim-header-i
- https://github.com/rspamd/rspamd/issues/2136
Future:
DKIM Replay Attack
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#DKIM_Replay_Attack
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Server_Security_Guide#DKIM_Replay_Attack|DKIM Replay Attack]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[DKIM Replay Attack](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#DKIM_Replay_Attack)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[DKIM Replay Attack](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#DKIM_Replay_Attack)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#DKIM_Replay_Attack]DKIM Replay Attack[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
- https://wordtothewise.com/2014/05/dkim-replay-attacks/
- https://tools.wordtothewise.com/rfc/6376#section-8.6
- https://www.socketlabs.com/blog/dkim-replay-attacks-preventive-measures-to-protect-email-deliverability/
Could a DKIM replay attack be resolved by enforcing In theory, yes. In practice, unsupported by DMARC. See DMARC Alignment: Enforce messages pass BOTH SPF and DKIM. And unlikely to be ever implemented since this would break the e-mail forwarding use case.
DKIM Required
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#DKIM_Required
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Server_Security_Guide#DKIM_Required|DKIM Required]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[DKIM Required](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#DKIM_Required)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[DKIM Required](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#DKIM_Required)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#DKIM_Required]DKIM Required[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Is SPF + DMARC sufficient or would this lead to ending up in the spam folder?
- DMARC will
pass
(success, not a failure) when either SPF or DMARC haspass
.- Such as
pass
(as in DMARC reports) however does only indicate that DMARC waspass
. The e-mail could still end up being rejected for being spam or end up in the spam folder.
- Such as
- Quote https://emfluence.com/blog/how-dkim-affects-email-deliverability
:
Yahoo! requires DKIM to sign up for their Feedback Loop (where they keep track of spam complaints). That means anyone who doesn’t have DKIM set up isn’t capturing spam complaints at Yahoo!, and because of that, those email addresses aren’t being suppressed automatically. That could put you on the road to being blocked or blacklisted by Yahoo!
- https://dmarcly.com/blog/can-i-set-up-dmarc-without-dkim
doesn't mention spam.
- Quote https://support.google.com/a/answer/174124?hl=en
:
Without DKIM, messages sent from your organization or domain are more likely to be marked as spam by receiving mail servers.
e-mail self hosting is hard
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#e-mail_self_hosting_is_hard
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Server_Security_Guide#e-mail_self_hosting_is_hard|e-mail self hosting is hard]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[e-mail self hosting is hard](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#e-mail_self_hosting_is_hard)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[e-mail self hosting is hard](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#e-mail_self_hosting_is_hard)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#e-mail_self_hosting_is_hard]e-mail self hosting is hard[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
- https://www.reddit.com/r/selfhosted/comments/xoi5im/google_smtp_low_domain_reputation/
- and google postmaster tools don't help https://www.tablix.org/~avian/blog/archives/2019/04/google_is_eating_our_mail/
- https://superuser.com/questions/1718259/google-bounce-email-with-error-550-5-7-1-our-system-has-detected-that-this-messa
- https://support.google.com/mail/thread/13395379/domain-reputation-got-bad-and-not-restoring-for-1-5-months-all-messages-bounced-back-with-550-5-7
rain dance required:
SPF
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#SPF
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Server_Security_Guide#SPF|SPF]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[SPF](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#SPF)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[SPF](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#SPF)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#SPF]SPF[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
SPF mostly ignored:
- "SPF is terrible, but was necessary"
Headers
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Headers
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Server_Security_Guide#Headers|Headers]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Headers](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Headers)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Headers](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Headers)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Headers]Headers[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
View e-mail headers:
- For example in Thunderbird: select an e-mail ->
View
->Message Source
There are two different "From" fields in an e-mail.
- A) 'MAIL FROM' https://en.wikipedia.org/wiki/Bounce_address
- B) 'From' header https://en.wikipedia.org/wiki/Email#Message_header
Very good explanation here: https://www.xeams.com/difference-envelope-header.htm
Checking DKIM Signatures on the Command Line
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Checking_DKIM_Signatures_on_the_Command_Line
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Server_Security_Guide#Checking_DKIM_Signatures_on_the_Command_Line|Checking DKIM Signatures on the Command Line]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Checking DKIM Signatures on the Command Line](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Checking_DKIM_Signatures_on_the_Command_Line)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Checking DKIM Signatures on the Command Line](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Checking_DKIM_Signatures_on_the_Command_Line)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Checking_DKIM_Signatures_on_the_Command_Line]Checking DKIM Signatures on the Command Line[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Might be mostly only useful for learning and testing purposes.
Install dkimverify
.
Install package(s) python3-dkim
following these instructions
1 Platform specific notice.
- Kicksecure: No special notice.
- Kicksecure-Qubes: In Template.
2 Update the package lists and upgrade the system.
Click = Copy Copied to clipboard! sudo apt update && sudo apt full-upgrade
3 Install the python3-dkim
package(s).
Using apt
command line --no-install-recommends
option is in most cases optional.
Click = Copy Copied to clipboard! sudo apt install --no-install-recommends python3-dkim
4 Platform specific notice.
- Kicksecure: No special notice.
- Kicksecure-Qubes: Shut down Template and restart App Qubes based on it as per Qubes Template Modification
.
5 Done.
The procedure of installing package(s) python3-dkim
is complete.
Click = Copy Copied to clipboard! dkimverify < e-mail.eml
Abuse Notifications
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Abuse_Notifications
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Server_Security_Guide#Abuse_Notifications|Abuse Notifications]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Abuse Notifications](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Abuse_Notifications)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Abuse Notifications](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Abuse_Notifications)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Abuse_Notifications]Abuse Notifications[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
- consider signing up for https://www.abuse.net/addnew.phtml
Standard E-Mail Addresses
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Standard_E-Mail_Addresses
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Server_Security_Guide#Standard_E-Mail_Addresses|Standard E-Mail Addresses]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Standard E-Mail Addresses](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Standard_E-Mail_Addresses)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Standard E-Mail Addresses](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Standard_E-Mail_Addresses)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Standard_E-Mail_Addresses]Standard E-Mail Addresses[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
- a number of standard e-mail addresses
should redirect to the inbox of the server administrator
Miscellaneous Server Tests
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Miscellaneous_Server_Tests
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Server_Security_Guide#Miscellaneous_Server_Tests|Miscellaneous Server Tests]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Miscellaneous Server Tests](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Miscellaneous_Server_Tests)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Miscellaneous Server Tests](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Miscellaneous_Server_Tests)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Miscellaneous_Server_Tests]Miscellaneous Server Tests[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
- See also Website and Server Tests.
- https://www.ssllabs.com/
- https://www.hardenize.com/
- https://www.sshaudit.com/
- https://hstspreload.org/
- https://securityheaders.com/
- https://clickjacker.io
- https://www.validbot.com/
- https://realfavicongenerator.net/
- https://sitecheck.sucuri.net/
- https://hostedscan.com/
- https://talosintelligence.com/
- https://www.debugbear.com/resource-hint-validator
- https://www.debugbear.com/test/website-speed
- https://developers.google.com/search/docs/appearance/structured-data
- https://pagespeed.web.dev/
- https://www.giftofspeed.com/gzip-test/
- https://gtmetrix.com/
- https://www.webpagetest.org/
- https://technicalseo.com/tools/robots-txt/
- https://www.cloudflare.com/ssl/encrypted-sni/
See Also
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#See_Also
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Server_Security_Guide#See_Also|See Also]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[See Also](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#See_Also)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[See Also](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#See_Also)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#See_Also]See Also[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Footnotes
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Footnotes
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Server_Security_Guide#Footnotes|Footnotes]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Footnotes](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Footnotes)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Footnotes](https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Footnotes)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Server_Security_Guide?direction=prev&oldid=91829#Footnotes]Footnotes[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.


Copy as Wikitext

for Discourse, reddit, GitHub

Copy as Markdown

Copy as phpBB Click below ↴ = Open social URL with share data











We believe security software like Kicksecure needs to remain Open Source and independent. Would you help sustain and grow the project? Learn more about our 12 year success story and maybe DONATE!