Northstar Dental
northstar-dental.example · External Security Assessment · August 24, 2026
- Exposures Found
- 5
- Categories Checked
- 8
- Confidence
- 100%
Summary
A stranger can act against northstar-dental.example today using information that is already public. The items marked Act Now should be closed first.
- 1Critical
- 1High
- 2Medium
- 1Low
Findings5
- Act Now10-minute DNS change
Anyone can send email that appears to come from you
Your domain publishes no DMARC policy, so a receiving mail server has no instruction to refuse a forged message. Someone can send an invoice from your address and it will be delivered.
- Evidence
No DMARC record found at _dmarc.northstar-dental.example- Remedy
- Publish a DMARC record starting at p=none with a reporting address, read the reports, then move to p=reject.
- Confirmed By
- Two independent DNS resolvers
- Act This Weekremote configuration
Six staff addresses appear in public breach data
Addresses at your domain appear in datasets anyone can download. The risk is a password reused somewhere that still works.
- Evidence
6 addresses across 4 sources, most recent 2025- Remedy
- Force a password reset for the affected accounts and turn on two-step login.
- Confirmed By
- Supported breach dataset
- Act This Month10-minute DNS change
A lookalike domain is configured to receive mail
A domain one character from yours is registered and has a mail server. That combination is preparation rather than coincidence.
- Evidence
northstardental.example is registered and has live mail servers- Remedy
- Publish DMARC at p=reject on your real domain and tell staff to confirm payment changes by phone.
- Confirmed By
- Registration and DNS lookup
- Act This Monthremote configuration
Your certificate expires in 19 days
When it lapses, visitors see a browser warning telling them the site is unsafe.
- Evidence
Certificate valid until 2026-09-12- Remedy
- Renew the certificate, and turn on automatic renewal so this cannot recur.
- Confirmed By
- TLS handshake
- Worth Fixing10-minute DNS change
Any certificate authority in the world can issue for your domain
Without a CAA record, nothing limits which authority may issue a certificate in your name.
- Evidence
No CAA record published- Remedy
- Publish a CAA record naming the authority you actually use.
- Confirmed By
- Two independent DNS resolvers