Knowledge Center

Guides, deep analyses and news about web security.

ERR_CERT_DATE_INVALID: What It Means and How to Fix It
Guides 9 min

ERR_CERT_DATE_INVALID: What It Means and How to Fix It

NET::ERR_CERT_DATE_INVALID means the certificate is outside its validity window right now. Google's data shows a wrong device clock causes it far more often than an expired certificate. Here is how to tell which it is, and how to fix both.

Johan HolmRead more
How to Read DMARC Reports: A Field-by-Field Guide to Aggregate XML
Security 9 min

How to Read DMARC Reports: A Field-by-Field Guide to Aggregate XML

DMARC aggregate reports look hostile but have only three sections. This guide walks through a real RFC 9990 report field by field, shows the seven row patterns you will actually see, and tells you what to do about each one.

David LindgrenRead more
How to Renew an SSL Certificate: Step-by-Step Guide for 2026
Guides 10 min

How to Renew an SSL Certificate: Step-by-Step Guide for 2026

Renew an SSL certificate the right way: Certbot commands for Let's Encrypt, the CSR and validation flow for paid certificates, hosting panel and CDN renewals, and how to verify the new certificate is live. Updated for the 200-day and 47-day lifetime rules.

Johan HolmRead more
SSL Certificate Expired: What Happens and How to Fix It Fast
Guides 8 min

SSL Certificate Expired: What Happens and How to Fix It Fast

An expired SSL certificate replaces your site with a browser warning and breaks APIs outright. Here is exactly what happens, the commands to check and fix it, and why shrinking lifetimes make automation mandatory in 2026.

Sofia BergströmRead more
Website Incident Response: A Step-by-Step Playbook for IT Managers
Guides 17 min

Website Incident Response: A Step-by-Step Playbook for IT Managers

A complete NIST-based incident response plan sized for small IT teams: severity levels, contact cards, tested backups, containment without destroying evidence, GDPR 72-hour notification and blameless post-mortems.

FortifyNet Security TeamRead more
Hardening HTTP Security Headers: A Step-by-Step Implementation Guide
Guides 15 min

Hardening HTTP Security Headers: A Step-by-Step Implementation Guide

From an F grade to a hardened A: deploy HSTS, nosniff, frame protection and Permissions-Policy immediately, then roll out Content-Security-Policy in three safe stages — with nginx and Apache configs.

FortifyNet Security TeamRead more
The Complete Email Authentication Rollout: SPF, DKIM & DMARC from Zero to p=reject
Guides 16 min

The Complete Email Authentication Rollout: SPF, DKIM & DMARC from Zero to p=reject

A 6–10 week, step-by-step enforcement plan for IT managers: inventory every sender, publish correct SPF and DKIM, read DMARC reports, and ramp safely to p=reject without losing a single legitimate email.

FortifyNet Security TeamRead more
Website Security Audit: The Complete 2026 Guide
Guides 7 min

Website Security Audit: The Complete 2026 Guide

What a website security audit actually checks, the four levels of depth available, and an eight step process you can run this week.

Johan HolmRead more
DMARC Monitoring: How to Read Your Reports and Reach p=reject Safely
Security 7 min

DMARC Monitoring: How to Read Your Reports and Reach p=reject Safely

More than half of all domains with a DMARC record collect no reports at all. Here is how DMARC monitoring works, how to read an aggregate report, what RFC 9990 changed in 2026, and how to reach p=reject without blocking your own mail.

David LindgrenRead more
SPF Record Syntax Explained: Mechanisms, Qualifiers and Limits
Security 8 min

SPF Record Syntax Explained: Mechanisms, Qualifiers and Limits

An SPF record is one DNS TXT record that starts with v=spf1, lists your authorized senders and ends with an all mechanism. Here is every mechanism, every qualifier and every hard limit in RFC 7208 that quietly breaks records which otherwise look fine.

David LindgrenRead more
ERR_CERT_COMMON_NAME_INVALID: What It Means and How to Fix It
Guides 8 min

ERR_CERT_COMMON_NAME_INVALID: What It Means and How to Fix It

The certificate is real and unexpired, but it was issued for different names than the one in your address bar. Here is what causes ERR_CERT_COMMON_NAME_INVALID and how both visitors and site owners can fix it.

Johan HolmRead more
X-Frame-Options: What It Does and How to Configure It Right
Security 7 min

X-Frame-Options: What It Does and How to Configure It Right

X-Frame-Options tells browsers whether your site may be embedded in a frame, and it is the classic defense against clickjacking. Here is how DENY and SAMEORIGIN work, which values silently fail, and when to switch to CSP frame-ancestors.

David LindgrenRead more
ERR_CERT_AUTHORITY_INVALID: What Causes It and How to Fix It
Guides 8 min

ERR_CERT_AUTHORITY_INVALID: What Causes It and How to Fix It

NET::ERR_CERT_AUTHORITY_INVALID means the browser could not build a trust path from your certificate back to a root it trusts. Here are the seven causes, how to tell server faults from device faults in 30 seconds, and the exact fix for each.

Johan HolmRead more
Pingdom Alternative: The 7 Best Options in 2026
Guides 7 min

Pingdom Alternative: The 7 Best Options in 2026

Pingdom has no free tier and its entry plan includes just 10 checks. Here are the six best Pingdom alternatives in 2026, compared on free tiers, check intervals, alerting and price.

Sofia BergströmRead more
GTmetrix Alternative: The 6 Best Options in 2026
Guides 7 min

GTmetrix Alternative: The 6 Best Options in 2026

GTmetrix Basic now gives you 5 tests a month for three months. Here are the six best GTmetrix alternatives in 2026, compared on free-tier limits, test locations, data retention and price.

Sofia BergströmRead more
What Is DKIM? DomainKeys Identified Mail Explained (2026 Guide)
Security 8 min

What Is DKIM? DomainKeys Identified Mail Explained (2026 Guide)

DKIM adds a cryptographic signature to every email your domain sends, so receiving servers can prove the message is genuine and unaltered. Here is how it works, how to set it up, and the mistakes that quietly break it.

David LindgrenRead more
Mozilla Observatory Alternative: The Best Replacements in 2026
Security 8 min

Mozilla Observatory Alternative: The Best Replacements in 2026

Mozilla Observatory was sunset in September 2024 and its MDN successor tests HTTP headers only. Here are the best replacements for 2026, compared side by side.

Erik LindgrenRead more
ERR_SSL_PROTOCOL_ERROR: What It Means and How to Fix It
Guides 7 min

ERR_SSL_PROTOCOL_ERROR: What It Means and How to Fix It

ERR_SSL_PROTOCOL_ERROR appears when the TLS handshake between browser and server breaks down. Here is what triggers it, and how visitors and site owners can fix it for good.

Johan HolmRead more
Website Security Checklist: 12 Essential Steps for 2026
Guides 8 min

Website Security Checklist: 12 Essential Steps for 2026

From HTTPS and security headers to DMARC, backups and dark-web monitoring: a practical 12-step website security checklist for 2026, with priorities, cadence and a data-backed FAQ.

Johan HolmRead more
How to Set Up DMARC, Step by Step (From p=none to p=reject)
Security 8 min

How to Set Up DMARC, Step by Step (From p=none to p=reject)

Gmail, Yahoo and Outlook now expect DMARC on sending domains. This step-by-step guide takes you from your first p=none record to full p=reject enforcement - reports, alignment fixes and all - without losing legitimate mail.

David LindgrenRead more
What Is HSTS? HTTP Strict Transport Security Explained
Security 7 min

What Is HSTS? HTTP Strict Transport Security Explained

HSTS tells browsers to load your site over HTTPS only - no downgrades, no click-through on certificate errors. Here's how it works, how to enable it on nginx, Apache, IIS and Cloudflare, and how to preload it safely.

David LindgrenRead more
"Your Connection Is Not Private": What It Means and How to Fix It
Guides 7 min

"Your Connection Is Not Private": What It Means and How to Fix It

The "Your connection is not private" warning means your browser could not verify a site's TLS certificate. Here is what causes it - and how to fix it for good.

Johan HolmRead more
SPF Record Checker: How to Test, Read, and Fix Your SPF Record
Security 8 min

SPF Record Checker: How to Test, Read, and Fix Your SPF Record

An SPF record checker tells you in seconds whether your domain can be spoofed. Here's how to read, test and fix your SPF record - and pass the new Gmail, Yahoo and Microsoft rules.

Johan HolmRead more
Website Vulnerability Scanner: What It Checks and How to Read Results
Security 7 min

Website Vulnerability Scanner: What It Checks and How to Read Results

What a website vulnerability scanner checks, how to read the report and fix the issues that matter most, plus how to choose the right scanner.

Johan HolmRead more
Best MX Toolbox Alternatives in 2026 (Honest Review)
Security 9 min

Best MX Toolbox Alternatives in 2026 (Honest Review)

MX Toolbox is a well-known name for DNS and email diagnostics. But is it still the best option in 2026? We break down the top alternatives - and why FortifyNet leads the pack.

Erik LindgrenRead more
GDPR & Security Audits: A Practical Guide for Website Owners
Compliance 13 min

GDPR & Security Audits: A Practical Guide for Website Owners

A practical overview of what GDPR means for your website's technical security. This is a general guide - always consult a legal advisor for advice specific to your situation.

Emma KarlssonRead more
Dark Web Monitoring: How to Detect if Your Business Data Has Been Breached
Dark Web 10 min

Dark Web Monitoring: How to Detect if Your Business Data Has Been Breached

A practical guide to understanding dark web exposure, detecting breached credentials, and responding to data breach incidents.

Johan HolmRead more
HTTP Security Headers: The Complete 2026 Guide with nginx & Apache Examples
Security 15 min

HTTP Security Headers: The Complete 2026 Guide with nginx & Apache Examples

Master HSTS, CSP, X-Frame-Options, and all critical security headers with ready-to-use configuration examples for nginx and Apache.

David LindgrenRead more
DNS Security Configuration: SPF, DMARC, DNSSEC & CAA Explained
Security 14 min

DNS Security Configuration: SPF, DMARC, DNSSEC & CAA Explained

A comprehensive guide to securing your domain's DNS configuration, preventing email spoofing, and protecting against DNS hijacking.

David LindgrenRead more
SSL/TLS Certificate Security: The Complete Guide to Achieving A+ Rating
Guides 12 min

SSL/TLS Certificate Security: The Complete Guide to Achieving A+ Rating

Everything you need to know about SSL/TLS configuration to achieve a top A+ rating and maximum security for your website.

Johan HolmRead more
Core Web Vitals 2026: What You Need to Know for Your Google Ranking
Performance 11 min

Core Web Vitals 2026: What You Need to Know for Your Google Ranking

Google updated Core Web Vitals criteria. Here is what has changed and how to optimize your website for better performance and SEO.

Emma KarlssonRead more

Cookie Settings

We use cookies to improve your experience. You can choose which cookies to accept.