Paul Rudenko
Security Researcher
Paul Rudenko is a security researcher and the person behind MySecScan's external scanning methodology. He works on how an attacker's view of a website — its TLS configuration, HTTP response headers, DNS and email authentication, exposed files and open services — can be measured passively and turned into clear, prioritised fixes.
His focus is the practical end of web security: the configuration-level defences that most sites can deploy in an afternoon but frequently miss, and the small set of issues that are actually being exploited in the wild rather than the long tail of theoretical findings.
He writes the MySecScan guides to be the explanation he wishes existed when first hardening a production site — accurate, vendor-neutral, and grounded in the relevant RFCs and the OWASP Secure Headers Project rather than copied checklists.
Guides by Paul Rudenko
- HTTP Security Headers: The Complete Guide (2026) →
- Email Authentication: SPF, DKIM & DMARC Explained →
- Website Security: How to Check and Improve Your Score →
- SSL/TLS Errors: What They Mean and How to Fix Them →
- How to Fix ERR_SSL_PROTOCOL_ERROR →
- How to Fix "Your Connection Is Not Private" →
- How to Fix "This Site Can't Provide a Secure Connection" →
- How to Fix NET::ERR_CERT_AUTHORITY_INVALID →
- How to Fix NET::ERR_CERT_DATE_INVALID →
- How to Fix SSL Handshake Failed →
- How to Fix an Expired SSL Certificate →
- How to Set Up SPF, DKIM and DMARC on GoDaddy →
- How to Set Up SPF, DKIM and DMARC for Google Workspace →
- How to Set Up SPF, DKIM and DMARC on Microsoft 365 (Office 365) →
- Why Your DMARC Is Failing (and How to Fix It) →
- How to Fix "DMARC Policy Not Enabled" (Quarantine/Reject Not Enabled) →
- How to Fix SPF Too Many DNS Lookups (PermError) →
- How to Fix Multiple SPF Records on One Domain →
- How to Prevent Email Spoofing of Your Domain →
- How to Add Security Headers in Nginx →
- How to Add Security Headers in Apache →
- How to Add Security Headers with Cloudflare →
- Content-Security-Policy (CSP): A Practical Guide →
- HSTS and the Preload List: A Complete Guide →
- Clickjacking: X-Frame-Options vs CSP frame-ancestors →
- CSP frame-ancestors: The Modern Clickjacking Defense →
- HSTS Test: Check Your Strict-Transport-Security Header →
- X-Content-Type-Options: nosniff Explained →
- Website Security Checklist (2026) →
- Why Does My Website Say "Not Secure" (and How to Fix It) →
- How to Improve Your Website Security Score →
- Cookie Security: Secure, HttpOnly and SameSite Explained →
- The Secure Cookie Flag: What It Does and How to Set It →
- The HttpOnly Cookie Flag: Stopping XSS Session Theft →
- The SameSite Cookie Attribute: Lax, Strict and None →
- Partitioned Cookies (CHIPS): What They Are and When You Need Them →
- How to Rate-Limit Your Login Page: Brute-Force & Credential-Stuffing Protection →
- How to Stop Brute-Force Login Attacks →
- Credential Stuffing: What It Is and How to Prevent It →
- HTTP 429 Too Many Requests: What It Means and How to Return It →
- UFW Firewall Guide: Protecting Your Linux Server →
- SSH Security Guide: Keys, Root Login, and Hardening →