📚 Resources

Website security, in plain English

Practical guides for Australian small businesses on email deliverability, web security, DNS, and privacy compliance. Written by the team behind the scanner.

Privacy and Compliance · 7 min read

Cookie consent that actually meets the OAIC standard for Australian websites

Most Australian small business cookie banners don't meet the OAIC's informed-consent standard. Here is what does, what doesn't, and how to fix it without paying for an enterprise consent platform.

Read article →
Web Security · 7 min read

Security headers explained for non-technical site owners (with copy-paste examples)

Six HTTP headers stop the most common attacks against your website. Here is what each one does in plain English, and the exact lines to add to nginx, Apache, or your WordPress config.

Read article →
WordPress and CMS · 8 min read

WordPress security hardening checklist for non-developers

WordPress runs over 40% of websites and is the most-targeted CMS on the internet. The good news: a clear ten-step hardening checklist closes most attacks, and none of the steps require a developer.

Read article →
Privacy and Compliance · 8 min read

Privacy Act 2024 amendments: what every Australian website owner needs to do

What the Privacy and Other Legislation Amendment Act 2024 actually changes for Australian website owners, what is still being debated in tranche 2, and the five practical things every site should review this quarter.

Read article →
Email Deliverability · 4 min read

Your domain is on a Spamhaus blacklist. Here is how to get it off.

A practical, plain-English guide for Australian small businesses whose customers stopped receiving their emails.

Read article →
DNS and Infrastructure · 7 min read

DNSSEC explained, and how to turn it on at popular Australian registrars

Your scanner says DNSSEC is not enabled. Here is what that actually means for your domain, why it matters, and how to flip it on at GoDaddy, Crazy Domains, Cloudflare, and Synergy Wholesale.

Read article →
Email Deliverability · 8 min read

SPF, DKIM, and DMARC explained for Australian small businesses (with copy-paste DNS examples)

Three DNS records decide whether your business email lands in the inbox or junk folder. Here is what each one does, why all three matter, and the exact records to add.

Read article →