Security Blog
Practical explainers and tutorials on hashing, encryption, DNS, email security and web app hardening — every post links to a free tool you can use right now, in your browser.
Caesar Cipher: How It Works, Examples, and How to Break It
Caesar cipher explained: how the shift cipher works, worked examples, how to break it with a Caesar cipher decoder, and the Vigenère and XOR ciphers.
DNSSEC Explained: How Signed Domains Prevent DNS Spoofing
Use a DNSSEC checker to verify your DS records and validation flags, and see how signed domains with DNS security extensions stop spoofing attacks.
SPF, DKIM and DMARC: How to Check Your Domain's Email Security
Run a free SPF, DKIM and DMARC check on any domain, fast. See why your email lands in spam and how to fix your email security posture in minutes.
How to Check if a Password Has Been Leaked
Learn how to check if a password leaked in a breach with Have I Been Pwned's k-anonymity API, and why reusing passwords is dangerous.
HMAC Explained: Why Keyed Hashing Beats Plain Hashing
What is HMAC? Learn how keyed hashing differs from plain hashing, how HMAC-SHA256 works, and where it's used for API signatures and JWTs.
OWASP API Security Top 10 Explained
OWASP API Security Top 10 2023 explained: the API security risks behind each entry, with realistic examples, including BOLA.
Password Entropy Explained (and How to Calculate It)
Password entropy explained: why length beats complexity, how to calculate bits of entropy, and what it means for your passphrases.
How Password Hash Cracking Works (and How to Defend Against It)
See how password hash cracking works: dictionary and brute-force attacks on MD5, NTLM and SHA-1 hashes, plus how to defend your own passwords.
Port Scanning Explained: What Open Ports Reveal About a Host
Learn what a port scan reveals about a host: TCP connect scanning, how to check open ports, common service ports, and scanning responsibly.
How to Scan a Website's Security Headers
Scan a live site's security headers with a free security header scanner to get an A-F grade, find missing protections, and pass an HTTP header audit.
Security Headers Checklist: The 8 Headers Every Site Should Ship
Security headers list: the 8 HTTP security headers every production site should ship, with recommended values, including the CSP header.
SHA-256 Checksum: How to Verify File Integrity
Learn how to verify a file hash with a SHA-256 checksum calculator on macOS, Linux, and Windows, and what to do when checksums don't match.
SPF and DMARC Record Generator Guide
Generate correct SPF and DMARC records with this guide. Learn SPF policy syntax, alignment, and common mistakes before you publish.
SSH Key Fingerprints: What They Are and How to Check Them
What is an SSH fingerprint? Learn to check a host key fingerprint with ssh-keygen -lf, and verify the server you connect to is the right one.
TOTP vs HOTP: How One-Time Passwords Work
TOTP vs HOTP explained: learn how one-time passwords work, how authenticator apps generate codes, and how to test TOTP secrets safely.