Repeatable website, DNS & Cloudflare security baselines for client-facing teams
Turn ad-hoc client security into a standard baseline you can run on every site, hand over as client-ready evidence, and repeat on onboarding — using a free, practical checklist. No retainer, no theatre.
Built by Myles Agnew · 18+ years in tech · Cloudflare, AWS, Azure, GCP, WordPress · Sydney, AU
The problem you already know
DNS mistakes take clients down
A bad record change or an un-backed-up zone turns a five-minute edit into an outage — and there's no known-good state to restore to.
Reviews aren't repeatable
Security depends on who did the work and what they remembered. Every engagement starts from scratch instead of a standard baseline.
Clients want proof, not reassurance
"We secured it" doesn't cut it anymore. Clients increasingly expect to see what was checked, what was fixed, and what's monitored.
Onboarding has no security floor
New client sites arrive with unknown DNS, Cloudflare, and WordPress state — and no consistent first-pass to bring them to a safe baseline.
The baseline
A practical 25-point review across the five places client sites actually break:
- DNS & domain — registrar MFA, expiry, off-platform record backup, SPF/DKIM/DMARC
- Cloudflare — proxy status, Always Use HTTPS, WAF, rate limiting, stale rules
- Security headers — HSTS, CSP, nosniff, Referrer-Policy, Permissions-Policy
- WordPress — updates, unused plugins, admin accounts, tested backups
- Recovery — off-platform DNS backup, restorable site, documented process
- Client-ready summary — findings, priorities, and evidence they can read
Free tools and checklists
Everything here is free to use — the checklist, the tools, and the security news. Run them yourself against your own client sites.
Who it's for
A good fit if you…
- Manage websites, DNS, or Cloudflare for clients
- Want a standard security floor for onboarding
- Need evidence clients can actually understand
- Prefer practical fixes over framework theatre
Probably not if you…
- Need formal certification/audit sign-off (ISO, SOC 2)
- Want a full managed SOC or 24/7 monitoring
- Are after enterprise GRC tooling and paperwork
Standardise client security without the overhead
Grab the free checklist and run it against your client sites, and subscribe for practical security updates and early access to new tools. No retainer, no theatre.