Skip to content

Home › Portfolio › DomRO.ro

DomRO.ro

DomRO.ro is a project where we fully applied the web security standards we recommend to you, verified with a security scanner across HTTP headers, TLS configuration, DNS zone signing, certificate authority restriction and email transport protection. The content policy was built from the cryptographic hashes of the scripts, covering both domain forms, and scored full marks on every checked category.

DomRO.ro

DomRO.ro is a project on which the web security standards recommended to clients were applied in full, from end to end.

1. About the project

The site went through a full security hardening process, verified with the security scanner, across every chapter: HTTP headers, TLS configuration, DNS zone signing, restriction of certificate issuance and protection of email transport.

2. The challenge

The hardest part of a strict content policy is not writing it, but the fact that it blocks silently. A legitimate script that does not match the policy simply does not run, with no message on the page. The problem surfaces only when a visitor reports that something is not working.

3. What we built

We generated the policy from the cryptographic fingerprints of every script in the site, calculated by walking all the pages automatically. Here we also discovered a trap that we carried over to other projects: pages were served from the bare domain while the theme requested its scripts from the prefixed variant, which caused dozens of invisible blocks. The policy now includes both forms of the domain explicitly.

4. The outcome

A perfect score across every chapter checked by the scanner, with a content policy that genuinely limits script sources rather than merely declaring that one exists. The final check is always done in a real browser, because blocks do not show up in the HTTP response code.

Other projects