Guide topic

Website, TLS and server security guides

Security guides covering TLS certificates, HTTPS, HSTS, security headers, mixed content, Linux firewalls, VPS hardening, SSH, access controls, and practical web-hosting security.

Security

Understand the system, not just the setting.

Hosting security is a set of layers: account access, operating systems, network exposure, TLS, application updates, browser policies, backups, and monitoring. These guides explain how the controls work together. No single header or firewall rule secures an entire application.

See DotMoose security approach

20 guides

Start with the problem you are solving.

All guide topics →
Security

Linux firewall setup: open only what the server needs

Plan Linux firewall rules around required services, management access, established traffic, IPv4/IPv6, provider firewalls, logging, and a safe rollback path.

Security

SSL certificate error: identify name, chain or date problems

SSL/TLS certificate errors can involve hostname mismatch, expiry, incomplete trust chain, untrusted issuer, clock issues, or the wrong certificate being served.

Security

SSL certificate expired: what to do before renewing blindly

An expired SSL/TLS certificate may indicate failed automation, DNS validation, wrong deployment path, stale proxy configuration, or a service no longer using the renewed certificate.

Security

HTTPS not working: test DNS, TLS and web-server layers

If HTTPS is not working, confirm DNS reaches the right server, port 443 is reachable, the TLS handshake succeeds, the certificate matches, and the web server has the correct virtual host.

Security

Mixed content warning: why an HTTPS page can still be insecure

Mixed content occurs when an HTTPS page requests resources over HTTP. Find hard-coded URLs, database content, stylesheets, scripts, images, proxies, and third-party dependencies.

Security

HSTS header setup: when to enable it and when to wait

HSTS tells browsers to use HTTPS for a host. Enable it only after HTTPS, redirects, certificates, renewal, subdomains, and rollback implications are understood.

Security

Website security headers: what the common headers do

Understand HSTS, Content-Security-Policy, frame controls, Referrer-Policy, Permissions-Policy, and why security headers need application-aware testing instead of a copied scorecard.

Security

TLS chain troubleshooting: fix incomplete or untrusted certificate paths

Inspect the leaf certificate, intermediates, trust path, hostname and server configuration to find why one client accepts HTTPS while another rejects it.

Security

TLS certificate renewal: replace a certificate without an HTTPS outage

Track expiry, automate renewal where appropriate, reload the serving process and verify the new chain externally before the old certificate becomes invalid.

Security

HSTS rollout planning: enable strict HTTPS without locking in a mistake

Stabilize HTTPS first, choose max-age carefully, cover subdomains deliberately and understand preload consequences before making HSTS hard to reverse.

Security

HTTPS redirect mistakes: loops, chains and host changes that hurt a site

Find conflicting HTTP-to-HTTPS and hostname redirects across proxies, servers and applications, then reduce the path to one intentional canonical destination.

Security

Security header rollout: add browser protections without breaking the site

Inventory current behaviour, deploy security headers one at a time, use report-only modes where available and verify login, checkout and embedded content.

Security

Content Security Policy rollout: build CSP from the resources a site really uses

Inventory scripts, styles, frames and connections, start with reporting, reduce unsafe allowances and enforce CSP only after normal user paths still work.

Security

Website security for beginners: hosting basics that matter first

A beginner website security guide covering unique passwords, MFA, updates, least privilege, HTTPS, backups, plugins, domain protection, email, and why a VPS is not automatically safer.

Security

VPS security checklist for a new Linux server

A practical Linux VPS hardening checklist covering access, updates, firewall rules, service exposure, backups, logs, TLS, secrets, and monitoring.

Security

SSL/TLS certificates explained for website owners

Understand HTTPS, TLS certificates, domain validation, certificate names, renewal, redirects, mixed content, HSTS, and what a certificate does not secure.

Linux

SSH key setup: how public-key login works

SSH key setup uses a private key on the client and an authorized public key on the server. Learn generation, installation, permissions, passphrases, rotation, and recovery.

WordPress

WordPress hosting checklist: what to verify before launch

A pre-launch WordPress checklist covering HTTPS, backups, updates, email delivery, DNS, security, performance, and recovery.

Email

Email deliverability checklist for small businesses

A practical business email checklist covering sending domains, SPF, DKIM, DMARC, reverse DNS, reputation, forms, newsletters, bounce handling, and testing.

Backups

Backup storage is not the same as file sync

What another copy should protect you from: deletion, ransomware, and hardware failure.