Overview
When reviewing your Digital Footprint, you may occasionally notice a score impact attributed to a specific subdomain, even if there are no active security issues directly tied to that subdomain's URL.
Why does my subdomain show a score impact if it has no issues?
In the SecurityScorecard platform, score impact is calculated not just by the domain or subdomain name, but also by the underlying infrastructure it relies on.
If a subdomain itself has no direct issues (for example, no missing secure cookie attributes on the domain level), it will correctly display zero direct issues. However, it will still display a score impact if the underlying IP addresses attached to that subdomain have active findings.
In these cases, the score impact is being inherited or "passed down" from the associated IPs to the subdomain.
Example
Screenshot 1: There is a finding associated with the URL [https://bank.example.com]
Note: The finding is attached to the parent asset example.com, not directly to bank.example.com.
Screenshot 2: In the Digital Footprint table, you can see that the subdomain bank.example.com shows 3 issues and a score impact of -0.6.
Screenshot 3: When reviewing the subdomain details, the score impact displays as -0.63 despite having no issues directly associated with it. The "Issues" tab only lists findings directly attached to bank.example.com. While this may seem inconsistent, the issue from Screenshot 1 is attached to example.com rather than bank.example.com.
Screenshot 4: Checking the IPs tab under the subdomain details reveals that the 3 issues and -0.63 score impact mentioned earlier are propagated from the underlying IP asset linked to bank.example.com