Transparent method
A narrow scan with a hard boundary.
OutClean measures only what a normal browser page load and public DNS disclose. The weighting totals 100 points and is the same for every verified domain.
Score weights
| Signal | Points |
|---|---|
| HTTPS and valid TLS | 20 |
| HTTP redirects to HTTPS | 5 |
| HSTS | 10 |
| Content Security Policy | 15 |
| Clickjacking protection | 10 |
| MIME sniffing protection | 5 |
| Referrer Policy | 4 |
| Permissions Policy | 4 |
| Cookie flags | 8 |
| No mixed content | 6 |
| No version banners | 3 |
| SPF | 5 |
| DMARC | 5 |
| Total | 100 |
Ranking
Higher effective security score ranks first. Equal scores are ordered by the most recent successful scan.
Raw scores remain fresh for 30 days. After that, one point is deducted for each started seven-day period, capped at 20 points. A successful re-scan replaces the raw score and resets its age.
Money and likes never affect rank. X engagement may place an entry in a separate Featured strip, but cannot alter table order.
Scan boundary
Included: one bounded document request, one same-host HTTP redirect observation, response headers, cookies returned with that document, inline HTML references, and public SPF/DMARC TXT records.
Excluded: endpoint enumeration, external-script retrieval, payloads, authentication attempts, port scanning, exploitation, and any domain without a verified ownership nonce.
Public record
We publish domain, score, color band, issue count, and scan date. Individual findings and vulnerability details remain private and are never included in a scorecard, badge, share text, or open-graph image.