All tools
Every check runs standalone here, or together as part of a full report card.
DNS
- DNS records
Every published DNS record for a domain, with TTLs and nameservers.
- Nameserver delegation
Checks a domain's nameservers for consistency across resolvers and confirms each one actually resolves.
- DNSSEC
Validates a domain's DNSSEC chain of trust and flags deprecated signing algorithms.
Email authentication
- SPF
Validates a domain's SPF record and counts the recursive DNS lookups against the limit of ten that receivers enforce.
- DKIM
Probes common DKIM selectors for a domain and reports the signing keys it finds, including key strength.
- DMARC
Reads a domain's DMARC policy and explains what receivers will actually do with mail that fails authentication.
- MTA-STS and TLS-RPT
Checks whether a domain requires TLS for inbound mail via MTA-STS, and whether it collects TLS failure reports.
HTTP security
- Security headers
Grades a site's HTTP security headers, including CSP, HSTS and cookie flags.
- HTTPS redirect & HSTS preload
Checks whether HTTP traffic is redirected to HTTPS, and this domain's HSTS preload list status.
- security.txt
Checks for a published RFC 9116 security.txt with a working contact and a current expiry date.
Domain registration
- Domain registration (RDAP/WHOIS)
Registrar, registration dates and expiry from RDAP, the structured successor to WHOIS.
TLS / certificates
- TLS certificates (Certificate Transparency)
Certificates issued for a domain, sourced from public Certificate Transparency logs — including subdomains you may not know have one.