---
title: #security — page 2 of 2
description: 31 articles about security — guides and explainers from the WatchFor team.
canonical: https://watchfor.io/blog/tag/security/page/2
---

[All posts](/blog)

# #security — page 2

Articles tagged "security".

[All](/blog)[Monitoring](/blog/category/monitoring)[Networking](/blog/category/networking)[Performance](/blog/category/performance)[Security](/blog/category/security)[Reliability](/blog/category/reliability)[Email](/blog/category/email)[DevOps](/blog/category/devops)[Engineering](/blog/category/engineering)

[All articles](/blog/all)

31 article s · page 2 of 2

[SecurityDec 20, 2025

## HSTS Explained: forcing browsers to always use HTTPS

You redirect HTTP to HTTPS — but that first insecure request is still a risk. HSTS closes that gap by telling browsers to never even try HTTP. Here's how it works and how to deploy it safely.WatchFor Team3 min read](/blog/hsts-explained)[SecurityDec 18, 2025

## What is a DDoS Attack? (and how to defend against one)

A DDoS attack drowns your service in traffic from thousands of sources until it buckles. Here's how these attacks work, the main types, and the practical layers of defence.WatchFor Team3 min read](/blog/what-is-a-ddos-attack)[SecurityDec 16, 2025

## What is a WAF (Web Application Firewall)?

A regular firewall guards the network; a WAF guards your application — inspecting web requests and blocking attacks like injection and bots. Here's how it works and what it does (and doesn't) cover.WatchFor Team3 min read](/blog/waf-explained)[SecurityDec 14, 2025

## Zero Trust Explained

The old security model trusted anyone inside the network. Zero Trust throws that out: trust nothing, verify everything, every time. Here's what it means in practice.WatchFor Team3 min read](/blog/zero-trust-explained)[SecurityDec 12, 2025

## What is a CVE? Vulnerability basics

When a security flaw is found in software, it gets a CVE — a global ID so everyone can track and fix it. Here's what CVEs are, how severity is scored, and how to stay on top of them.WatchFor Team3 min read](/blog/what-is-a-cve)[SecurityDec 10, 2025

## Secrets Management Explained

API keys, passwords and tokens are the keys to your kingdom — and they end up hard-coded, committed to git, and shared in chat far too often. Here's how to handle secrets properly.WatchFor Team3 min read](/blog/secrets-management)[SecurityDec 08, 2025

## What is mTLS (Mutual TLS)?

Normal HTTPS proves the server's identity to you. mTLS goes both ways — the client proves itself too. Here's what mutual TLS is, where it's used, and why it's a Zero Trust building block.WatchFor Team3 min read](/blog/mtls-explained)[SecurityDec 06, 2025

## Domain Spoofing and How to Prevent It

Scammers can send email that looks exactly like it's from your domain — phishing your customers and torching your reputation. Here's how domain spoofing works and how to lock it down.WatchFor Team3 min read](/blog/domain-spoofing)[SecurityDec 04, 2025

## DNSSEC Explained: signing DNS so it can't be faked

DNS was built without security — answers can be forged, sending users to fake servers. DNSSEC adds cryptographic signatures so resolvers can verify DNS answers are genuine. Here's how.WatchFor Team3 min read](/blog/dnssec-explained)[EmailNov 30, 2025

## How to Set Up DMARC (step by step)

DMARC is what actually stops scammers spoofing your domain — but rushing it can block your own email. Here's the safe, staged way to roll it out from monitoring to full enforcement.WatchFor Team3 min read](/blog/dmarc-setup-guide)[EmailNov 26, 2025

## BIMI Explained: your logo in the inbox

BIMI puts your brand's verified logo next to your emails in supporting inboxes — a trust signal and an anti-spoofing reward. Here's what it is, what it requires, and whether it's worth it.WatchFor Team3 min read](/blog/bimi-explained)

---

Canonical page: https://watchfor.io/blog/tag/security/page/2 · Site guide: https://watchfor.io/llms.txt
