> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.autophish.io/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# How to set up the Security Scan for your Domain

This guide shows you how to add a domain to the AutoPhish Security Center, run your first DNS & e-mail check, and optionally enable vulnerability scanning. Setup takes about two minutes.

## Step 1 – Open the Security Center
In the AutoPhish app, click **Security** in the top navigation. The Security Center opens and shows the Security Score, DNS health, vulnerabilities and threats for all domains of your company.
![](https://storage.crisp.chat/users/helpdesk/website/-/4/3/7/4/437439cedb096800/01-security-center-overview_1uos5la.jpg)

## Step 2 – Add your domain
Click **+ Add Domain** in the top right corner. Enter your domain name without http:// or www (for example: yourcompany.com) and confirm.
![](https://storage.crisp.chat/users/helpdesk/website/-/4/3/7/4/437439cedb096800/02-add-domain-dialog_g3duyl.jpg)

After adding the domain, you will be asked to verify domain ownership. Once your domain is verified, it appears in the Security Center and monitoring starts automatically.

## Step 3 – Check your DNS & e-mail results
The first DNS scan runs right after setup and is repeated automatically every day. Open the **DNS Health** tab to see the status of your SPF, DKIM and DMARC configuration and any issues that were found.
![](https://storage.crisp.chat/users/helpdesk/website/-/4/3/7/4/437439cedb096800/03-dns-health-tab_mfvrpp.jpg)

## Step 4 – Open the detailed domain view
Click **View** next to your domain in the Domain Health table. Here you find your current SPF, DKIM and DMARC records, threat findings such as look-alike domains, and the **Scan DNS** button to re-run the check on demand.
![](https://storage.crisp.chat/users/helpdesk/website/-/4/3/7/4/437439cedb096800/04-domain-detail_1x3m3hg.jpg)

## Step 5 – Enable vulnerability scans (optional)
Web and vulnerability scans are **disabled by default** – you decide per domain whether they run. To enable them, open the **Settings** tab in the domain view and switch **Vulnerability Scans** to Enabled. From then on, your public web services are checked automatically, and you can also start a scan manually with **Scan Vulnerabilities**.
![](https://storage.crisp.chat/users/helpdesk/website/-/4/3/7/4/437439cedb096800/05-domain-settings-vulnerabili_n2sn8e.jpg)

## Step 6 – Monitor your results
Findings appear in the **Vulnerabilities** and **Threats** tabs, grouped by severity and with a concrete recommendation for each finding. At the bottom of the Security Center you can always see when the last scan ran and when the next one is scheduled. With **Email Alerts** enabled, you are notified as soon as new security issues are detected.
![](https://storage.crisp.chat/users/helpdesk/website/-/4/3/7/4/437439cedb096800/06-vulnerabilities-tab_1q6lhmv.jpg)

## Good to know
The Security Scan looks at your infrastructure from the outside only – no agents, no credentials and no access to internal systems are required. It is a fast, repeatable early-warning system for publicly visible risks and complements, but does not replace, an in-depth penetration test.

Questions about your setup or your scan results? Reach out via chat – we are happy to help.