zoomdrain.com
Corporate / B2B site, served through cloudflare.
Email health7Needs work
You have DMARC set up, but in monitor-only mode — it's not actually rejecting spoofed mail.
No SPF record is published, so nothing tells mail providers who's allowed to send as you.
Branded domain email address (vs free Gmail/Yahoo)
Your published contact email is on a free service, not your own domain.
Mailto: direct contact link present
We couldn't find a tap-to-email link anywhere on your site.
6 additional standards didn't apply to this category
SEO44Needs work
Title, meta description, OG, Twitter cards, canonical
Your homepage is missing one or more of the standard social-share and search-preview tags.
Schema.org type validity (parsed JSON-LD)
We didn't find any structured-data tags on your homepage.
Internal link depth (clicks from homepage to deepest content)
Important pages are reachable in just a click or two from your homepage.
6 additional standards didn't apply to this category
Security
⚠ Held back by a critical issue
69Fair
Your site isn't sending any of the standard browser-protection headers.
Your server doesn't staple OCSP. Visitors' browsers may have to contact the CA themselves, slowing first connects.
Neither OCSP stapling nor Must-Staple is in play. A revoked cert wouldn't be caught quickly.
Your TLS handshake takes over a second on a cold connection. Move behind a CDN with TLS session resumption and 0-RTT.
Certificate key strength and signature algorithm
Your certificate uses outdated key strength or a SHA-1 signature. Reissue with a modern ACME-class cert.
Embedded SCT count (Certificate Transparency)
Your certificate carries only one embedded SCT — modern browsers want at least two. Reissue from a CA that includes them.
SSL certificate validity & expiration window
Your SSL certificate is valid and not close to expiring.
Sensitive path exposure (.git, .env, /admin, xmlrpc.php, wp-login.php)
None of the common admin or developer paths are publicly reachable.
Forward secrecy is guaranteed by the negotiated handshake — past traffic stays unreadable even if your key leaks.
Certificate chain completeness
Your server sends the full certificate chain — every device builds the path to a trusted root cleanly.
Certificate validity-period brevity
Your certificate uses a short validity window (≤ 90 days) — auto-renewal keeps revocation fast and frictionless.
Your certificate is issued by a tier-1 publicly trusted CA (Let's Encrypt, DigiCert, Google Trust, Sectigo, etc.).
9 additional standards didn't apply to this category
Performance79Strong
Your server still serves over the older HTTP/2 protocol — not the newer, faster HTTP/3.
Lazy loading on below-fold images
Images below the fold aren't lazy-loaded — visitors download them up front even if they never scroll that far.
Image optimization (WebP/AVIF)
Your images are served as JPEG or PNG when modern formats (WebP, AVIF) would cut their size by 30–60% with no visible loss.
Mobile PageSpeed score + Core Web Vitals (LCP, FCP, CLS)
Your homepage loads fast on mobile — the metrics Google uses for ranking are in the green.
Your homepage loads fast on desktop — Google's ranking signal is in the green.
Core Web Vitals from CrUX (Real User Monitoring)
Real visitors report fast loads in Chrome User Experience data — your live performance is genuinely good.
Font loading strategy (FOUT/FOIT/swap)
Your fonts swap in cleanly — text is readable in the system font while custom fonts download.
5 additional standards didn't apply to this category
Accessibility88Excellent
Your heading levels skip — for example, an H1 followed by an H3 with no H2 in between. Screen reader users lose the outline of the page.
axe-core / WAVE accessibility scan
Automated accessibility scans flagged issues on your homepage — alt text, contrast, ARIA labels, or heading structure problems that block real users.
ARIA labels presence and validity
Interactive elements have proper ARIA labels — screen reader users get a clear description of each control.
Every image on your homepage has alt text — screen readers can describe them.
Text on your homepage meets WCAG AA contrast minimums — readable by visitors with low vision.
2 additional standards didn't apply to this category
View formal standards verdicts → Composite-spec rollups for press, regulators, and compliance auditors.
12 additional standards planned, scorer not yet implemented.
Is email from this domain trustworthy?18Needs work
Stops scammers from emailing customers as you
You have DMARC set up, but in monitor-only mode — it's not actually rejecting spoofed mail.
Lists who's allowed to email as your business
No SPF record is published, so nothing tells mail providers who's allowed to send as you.
You email from your own domain, not Gmail
Your published contact email is on a free service, not your own domain.
A contact form people can actually find
We couldn't find a visible contact form on your homepage.
A clickable email link on your site
We couldn't find a tap-to-email link anywhere on your site.
6 additional standards didn't apply to this site
Can people find this site?48Needs work
How your site appears when shared or in search results
Your homepage is missing one or more of the standard social-share and search-preview tags.
Whether your behind-the-scenes labels are valid
We didn't find any structured-data tags on your homepage.
How easy it is to reach your deepest pages
Important pages are reachable in just a click or two from your homepage.
6 additional standards didn't apply to this site
Is it safe to visit?67Fair
Browser-level protections for visitors
Your site isn't sending any of the standard browser-protection headers.
Visitors connect faster on the first click
Your server doesn't staple OCSP. Visitors' browsers may have to contact the CA themselves, slowing first connects.
Strict mode for your padlock check
Neither OCSP stapling nor Must-Staple is in play. A revoked cert wouldn't be caught quickly.
Your site finishes its handshake quickly
Your TLS handshake takes over a second on a cold connection. Move behind a CDN with TLS session resumption and 0-RTT.
Your padlock isn't using outdated keys
Your certificate uses outdated key strength or a SHA-1 signature. Reissue with a modern ACME-class cert.
Your certificate is publicly logged
Your certificate carries only one embedded SCT — modern browsers want at least two. Reissue from a CA that includes them.
Your padlock isn't about to expire
Your SSL certificate is valid and not close to expiring.
Private files aren't open to the public
None of the common admin or developer paths are publicly reachable.
Old recordings stay locked even if a key leaks
Forward secrecy is guaranteed by the negotiated handshake — past traffic stays unreadable even if your key leaks.
Your padlock loads cleanly on every device
Your server sends the full certificate chain — every device builds the path to a trusted root cleanly.
Your padlock renews on a healthy schedule
Your certificate uses a short validity window (≤ 90 days) — auto-renewal keeps revocation fast and frictionless.
Your padlock comes from a reputable vendor
Your certificate is issued by a tier-1 publicly trusted CA (Let's Encrypt, DigiCert, Google Trust, Sectigo, etc.).
9 additional standards didn't apply to this site
Is it fast?71Strong
Your site uses the newest connection style
Your server still serves over the older HTTP/2 protocol — not the newer, faster HTTP/3.
Photos lower on the page wait their turn
Images below the fold aren't lazy-loaded — visitors download them up front even if they never scroll that far.
Your photos are saved in modern formats
Your images are served as JPEG or PNG when modern formats (WebP, AVIF) would cut their size by 30–60% with no visible loss.
How fast your site loads on a phone
Your homepage loads fast on mobile — the metrics Google uses for ranking are in the green.
How fast your site loads on a laptop
Your homepage loads fast on desktop — Google's ranking signal is in the green.
How real visitors actually experience your speed
Real visitors report fast loads in Chrome User Experience data — your live performance is genuinely good.
Your text shows up while fonts load
Your fonts swap in cleanly — text is readable in the system font while custom fonts download.
5 additional standards didn't apply to this site
Can everyone use it?79Strong
Your headings are in a sensible order
Your heading levels skip — for example, an H1 followed by an H3 with no H2 in between. Screen reader users lose the outline of the page.
Your site works for visitors with disabilities
Automated accessibility scans flagged issues on your homepage — alt text, contrast, ARIA labels, or heading structure problems that block real users.
Your buttons and forms are labeled for screen readers
Interactive elements have proper ARIA labels — screen reader users get a clear description of each control.
Your photos have written descriptions
Every image on your homepage has alt text — screen readers can describe them.
Text on your homepage meets WCAG AA contrast minimums — readable by visitors with low vision.
2 additional standards didn't apply to this site
Does this look like a real business?——
Does it respect visitor privacy?——
6 additional standards didn't apply to this site
Site signals
Context we detected about this site — presence, reputation, and the tools it runs. These are informational and don't affect the score, up or down.