pawzync.com
SaaS / Product site based in India, served through cloudflare, with email running through microsoft.
Email health37Needs work
No SPF record is published, so nothing tells mail providers who's allowed to send as you.
No MTA-STS or TLS-RPT policy is published — incoming mail could be downgraded to plaintext.
Branded domain email address (vs free Gmail/Yahoo)
Your published contact email is on a free service, not your own domain.
You have DMARC set up, but in monitor-only mode — it's not actually rejecting spoofed mail.
Mailto: direct contact link present
Your site exposes a mailto: link visitors can tap to start a message.
5 additional standards didn't apply to this category
SEO61Fair
Title, meta description, OG, Twitter cards, canonical
Your homepage is missing one or more of the standard social-share and search-preview tags.
Schema.org structured data presence
Your homepage doesn't publish any Schema.org structured data. Search engines and AI tools fall back to guessing what your site is — and they guess wrong more often than not.
Schema.org type validity (parsed JSON-LD)
We didn't find any structured-data tags on your homepage.
Your homepage has a clear H1 heading — search engines and screen readers know what the page is about.
Internal link depth (clicks from homepage to deepest content)
Important pages are reachable in just a click or two from your homepage.
4 additional standards didn't apply to this category
Performance66Fair
Your server still serves over the older HTTP/2 protocol — not the newer, faster HTTP/3.
Image optimization (WebP/AVIF)
Your images are served as JPEG or PNG when modern formats (WebP, AVIF) would cut their size by 30–60% with no visible loss.
Lazy loading on below-fold images
Images below the fold aren't lazy-loaded — visitors download them up front even if they never scroll that far.
Mobile PageSpeed score + Core Web Vitals (LCP, FCP, CLS)
Your homepage is mid-pack on mobile. Reasonable but Google's ranking signal rewards faster sites.
Your server isn't compressing pages before sending them. Visitors download more bytes than they need to.
Your homepage loads fast on desktop — Google's ranking signal is in the green.
Font loading strategy (FOUT/FOIT/swap)
Your fonts swap in cleanly — text is readable in the system font while custom fonts download.
5 additional standards didn't apply to this category
Accessibility77Strong
Your heading levels skip — for example, an H1 followed by an H3 with no H2 in between. Screen reader users lose the outline of the page.
No skip-to-content link is published. Keyboard users have to tab through every nav item on every page before reaching the content.
Text on your homepage doesn't meet WCAG AA contrast minimums against its background. Visitors with low vision can't read parts of the page.
axe-core / WAVE accessibility scan
Your homepage passes automated accessibility checks — no obvious blockers for screen readers or keyboard users.
Your accessibility statement page is published — visitors can find out what standards you commit to.
Every image on your homepage has alt text — screen readers can describe them.
ARIA labels presence and validity
Interactive elements have proper ARIA labels — screen reader users get a clear description of each control.
Security86Excellent
There's no CAA record at your registrar saying which companies are allowed to issue certificates for you.
Your domain isn't on Chrome's HSTS preload list. The first visit from a new browser still has a brief window where an attacker could intercept it.
Your server doesn't staple OCSP. Visitors' browsers may have to contact the CA themselves, slowing first connects.
Neither OCSP stapling nor Must-Staple is in play. A revoked cert wouldn't be caught quickly.
Your site isn't sending any of the standard browser-protection headers.
Embedded SCT count (Certificate Transparency)
Your certificate carries only one embedded SCT — modern browsers want at least two. Reissue from a CA that includes them.
Your TLS handshake is on the slower side. A CDN with anycast edges and session resumption usually cuts this in half.
SSL certificate validity & expiration window
Your SSL certificate is valid and not close to expiring.
Sensitive path exposure (.git, .env, /admin, xmlrpc.php, wp-login.php)
None of the common admin or developer paths are publicly reachable.
Modern cipher suite preference
The handshake negotiates a modern AEAD cipher (AES-GCM or ChaCha20-Poly1305).
Forward secrecy is guaranteed by the negotiated handshake — past traffic stays unreadable even if your key leaks.
Certificate key strength and signature algorithm
Your certificate uses strong modern math (ECDSA P-256+ or RSA-2048+ with SHA-256+).
Certificate chain completeness
Your server sends the full certificate chain — every device builds the path to a trusted root cleanly.
Certificate validity-period brevity
Your certificate uses a short validity window (≤ 90 days) — auto-renewal keeps revocation fast and frictionless.
Your certificate is issued by a tier-1 publicly trusted CA (Let's Encrypt, DigiCert, Google Trust, Sectigo, etc.).
4 additional standards didn't apply to this category
Privacy88Excellent
Your homepage loads a reasonable number of third-party services — clean privacy footprint.
3 additional standards didn't apply to this category
View formal standards verdicts → Composite-spec rollups for press, regulators, and compliance auditors.
9 additional standards planned, scorer not yet implemented.
Is email from this domain trustworthy?53Needs work
Lists who's allowed to email as your business
No SPF record is published, so nothing tells mail providers who's allowed to send as you.
Keeps your email private in transit
No MTA-STS or TLS-RPT policy is published — incoming mail could be downgraded to plaintext.
You email from your own domain, not Gmail
Your published contact email is on a free service, not your own domain.
Stops scammers from emailing customers as you
You have DMARC set up, but in monitor-only mode — it's not actually rejecting spoofed mail.
A contact form people can actually find
A visible contact form is reachable from your homepage.
A clickable email link on your site
Your site exposes a mailto: link visitors can tap to start a message.
5 additional standards didn't apply to this site
Is it fast?61Fair
Your site uses the newest connection style
Your server still serves over the older HTTP/2 protocol — not the newer, faster HTTP/3.
Your photos are saved in modern formats
Your images are served as JPEG or PNG when modern formats (WebP, AVIF) would cut their size by 30–60% with no visible loss.
Photos lower on the page wait their turn
Images below the fold aren't lazy-loaded — visitors download them up front even if they never scroll that far.
How fast your site loads on a phone
Your homepage is mid-pack on mobile. Reasonable but Google's ranking signal rewards faster sites.
Pages get squeezed before they're sent
Your server isn't compressing pages before sending them. Visitors download more bytes than they need to.
How fast your site loads on a laptop
Your homepage loads fast on desktop — Google's ranking signal is in the green.
Your text shows up while fonts load
Your fonts swap in cleanly — text is readable in the system font while custom fonts download.
5 additional standards didn't apply to this site
Can people find this site?65Fair
How your site appears when shared or in search results
Your homepage is missing one or more of the standard social-share and search-preview tags.
Hidden labels that explain your business to Google
Your homepage doesn't publish any Schema.org structured data. Search engines and AI tools fall back to guessing what your site is — and they guess wrong more often than not.
Whether your behind-the-scenes labels are valid
We didn't find any structured-data tags on your homepage.
A clear headline on every page
Your homepage has a clear H1 heading — search engines and screen readers know what the page is about.
How easy it is to reach your deepest pages
Important pages are reachable in just a click or two from your homepage.
4 additional standards didn't apply to this site
Is it safe to visit?72Strong
Only your approved vendors can issue your padlock
There's no CAA record at your registrar saying which companies are allowed to issue certificates for you.
Your site is on the browser-baked-in safe list
Your domain isn't on Chrome's HSTS preload list. The first visit from a new browser still has a brief window where an attacker could intercept it.
Visitors connect faster on the first click
Your server doesn't staple OCSP. Visitors' browsers may have to contact the CA themselves, slowing first connects.
Strict mode for your padlock check
Neither OCSP stapling nor Must-Staple is in play. A revoked cert wouldn't be caught quickly.
Browser-level protections for visitors
Your site isn't sending any of the standard browser-protection headers.
Your certificate is publicly logged
Your certificate carries only one embedded SCT — modern browsers want at least two. Reissue from a CA that includes them.
Your site finishes its handshake quickly
Your TLS handshake is on the slower side. A CDN with anycast edges and session resumption usually cuts this in half.
Your padlock isn't about to expire
Your SSL certificate is valid and not close to expiring.
Private files aren't open to the public
None of the common admin or developer paths are publicly reachable.
The padlock uses strong, modern math
The handshake negotiates a modern AEAD cipher (AES-GCM or ChaCha20-Poly1305).
Old recordings stay locked even if a key leaks
Forward secrecy is guaranteed by the negotiated handshake — past traffic stays unreadable even if your key leaks.
Your padlock isn't using outdated keys
Your certificate uses strong modern math (ECDSA P-256+ or RSA-2048+ with SHA-256+).
Your padlock loads cleanly on every device
Your server sends the full certificate chain — every device builds the path to a trusted root cleanly.
Your padlock renews on a healthy schedule
Your certificate uses a short validity window (≤ 90 days) — auto-renewal keeps revocation fast and frictionless.
Your padlock comes from a reputable vendor
Your certificate is issued by a tier-1 publicly trusted CA (Let's Encrypt, DigiCert, Google Trust, Sectigo, etc.).
4 additional standards didn't apply to this site
Can everyone use it?73Strong
Your headings are in a sensible order
Your heading levels skip — for example, an H1 followed by an H3 with no H2 in between. Screen reader users lose the outline of the page.
No skip-to-content link is published. Keyboard users have to tab through every nav item on every page before reaching the content.
Text on your homepage doesn't meet WCAG AA contrast minimums against its background. Visitors with low vision can't read parts of the page.
Your site works for visitors with disabilities
Your homepage passes automated accessibility checks — no obvious blockers for screen readers or keyboard users.
You have an accessibility statement
Your accessibility statement page is published — visitors can find out what standards you commit to.
Your photos have written descriptions
Every image on your homepage has alt text — screen readers can describe them.
Your buttons and forms are labeled for screen readers
Interactive elements have proper ARIA labels — screen reader users get a clear description of each control.
Does it respect visitor privacy?93Excellent
How many outside companies you let watch your visitors
Your homepage loads a reasonable number of third-party services — clean privacy footprint.
You have a terms of service page
Your terms of service page is reachable from the homepage.
3 additional standards didn't apply to this site
Does this look like a real business?——
Site signals
Context we detected about this site — presence, reputation, and the tools it runs. These are informational and don't affect the score, up or down.