Domain health check

Get a fast overview of the public DNS settings that support a website, email delivery, certificate issuance, and DNS integrity.

Checks public web, nameserver, email-authentication, certificate-authority, and DNSSEC records.

What the report checks

The report combines several public DNS signals into one readable checklist: web addresses, authoritative nameservers, MX routing, SPF, DMARC, CAA, and DNSSEC.

The score is deliberately conservative and contextual. A domain that does not receive email can be healthy without MX, SPF, or DMARC, while a mail-sending domain should review all three carefully.

Use the report as a starting point

  • Confirm warnings against the services the domain is intended to run.
  • Review mail authentication using real DMARC aggregate reports.
  • Test website and mail endpoints separately from DNS.
  • Recheck after the previous record TTL has expired.
  • Document expected providers so stale records are easier to spot.

Quick answers

Frequently asked questions

Is this a security scan?

No. It reviews public configuration signals and does not test applications, servers, accounts, or private infrastructure.

Why is CAA or DNSSEC shown as informational?

They are valuable controls, but their absence does not automatically mean a domain is broken. The appropriate configuration depends on the domain’s use.