Security Snapshot Report
Acme Digital Agency
acmedigital.io
March 28, 2026
External exposure review
Audita
Overall risk grade
Medium-High Risk
Acme Digital Agency has a moderate-to-high external risk exposure. Email authentication is partially configured, TLS is active but uses outdated protocols on some subdomains, and several services are unnecessarily exposed. These gaps could undermine client trust and create compliance friction.
3
Critical findings
4
Warnings
3
Passing checks
Email authentication & DNS hygiene
SPF Record
WarningConfigured but overly permissive (~all instead of -all)
DKIM
FailNot configured for primary domain acmedigital.io
DMARC
WarningPolicy set to p=none — monitoring only, no enforcement
MX Records
PassStandard Google Workspace configuration
Dangling DNS
Failstaging.acmedigital.io CNAME points to deprovisioned Heroku app
| Check | Finding | Status |
|---|---|---|
| SPF Record | Configured but overly permissive (~all instead of -all) | Warning |
| DKIM | Not configured for primary domain acmedigital.io | Fail |
| DMARC | Policy set to p=none — monitoring only, no enforcement | Warning |
| MX Records | Standard Google Workspace configuration | Pass |
| Dangling DNS | staging.acmedigital.io CNAME points to deprovisioned Heroku app | Fail |
Certificate & protocol review
acmedigital.ioPassTLS 1.3, valid certificate, HSTS enabled
portal.acmedigital.ioWarningTLS 1.2 only — certificate expires in 12 days
staging.acmedigital.ioFailTLS 1.0 / 1.1 still accepted — vulnerable to downgrade attacks
Wildcard certificateWarning*.acmedigital.io in use — increases blast radius if private key is compromised
| Target | Finding | Status |
|---|---|---|
acmedigital.io | TLS 1.3, valid certificate, HSTS enabled | Pass |
portal.acmedigital.io | TLS 1.2 only — certificate expires in 12 days | Warning |
staging.acmedigital.io | TLS 1.0 / 1.1 still accepted — vulnerable to downgrade attacks | Fail |
Wildcard certificate | *.acmedigital.io in use — increases blast radius if private key is compromised | Warning |
Publicly reachable services that should not be
SSH (port 22)
Critical203.0.113.42
Password authentication enabled on production IP
Node.js dev server (port 3000)
Highstaging.acmedigital.io
Development server publicly accessible
Elasticsearch (port 9200)
Criticalstaging IP
Responding without authentication — data exfiltration risk
Environment file
Criticalstaging.acmedigital.io/.env
Secrets, API keys, and database credentials exposed
Apache server-status
Medium203.0.113.42/server-status
Internal server metrics publicly accessible
Top 5 recommendations
Ordered by combined severity and ease of fix. Difficulty is rated from 1 (easy) to 3 (hard).
Rotate all secrets and remove exposed .env file
Credentials are publicly accessible — assume compromise. Rotate every secret referenced in the file, revoke API keys, and block direct file access.
Close Elasticsearch port and disable SSH password auth
Unauthenticated Elasticsearch access allows data exfiltration. SSH password auth on a production IP invites brute-force attacks.
Deploy DKIM and enforce DMARC to p=reject
Without DKIM and an enforced DMARC policy, attackers can spoof emails from your domain — damaging client trust and enabling phishing.
Renew portal TLS certificate and disable TLS 1.0/1.1
An expired certificate will break the client portal. Legacy TLS versions are vulnerable to POODLE and BEAST attacks.
Remove dangling staging DNS and decommission unused subdomains
A dangling CNAME is a subdomain takeover risk — an attacker could claim the Heroku endpoint and serve content on your domain.
Turn findings into fixes
This snapshot surfaces your most visible external risks. The next step is to address critical findings immediately, then work through the remediation plan. If you want a deeper review that includes internal controls, identity, access, and operational readiness — Audita’s full audit covers it all.
Step 1
Remediate critical items today — rotate secrets, close exposed ports, and block the .env file.
Step 2
Work through warnings over the next 30 days — deploy DKIM, enforce DMARC, and renew expiring certificates.
Step 3
Upgrade to the full Automated Security Audit for internal controls, identity review, and a 30/60/90 remediation roadmap.
This is a sample report for demonstration purposes. “Acme Digital Agency” is a fictional company. Actual reports are generated from live external checks against your real domain and infrastructure.
© 2026 Audita. All rights reserved.