Check a public domain for common browser security response headers. This is a passive check and does not exploit the target.
HSTS, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy, plus DNS/email signals returned by the Dominion Fortress domain scanner.