Domain and email diagnostics
Free checks for the DNS, mail and TLS configuration behind any domain — live lookups against public infrastructure, no account, nothing stored.
Email authentication
Whether SPF, DKIM, DMARC and MTA-STS are set up — and what each result actually means.
Email header analyser
Paste a message's raw headers to see every hop it took and what each server recorded about it.
SPF record analyser
Whether an SPF record actually evaluates — the DNS lookups it costs against the limit that breaks it.
MX and mail servers
Where a domain's mail goes, and which servers answer for it.
Reverse DNS check
Whether a sending IP has a reverse name, and whether that name resolves back to it.
DNS
DNS lookup
Every record behind a hostname: A, AAAA, MX, TXT, NS and CNAME.
DNSSEC check
Whether a domain's DNSSEC chain actually validates — and if it does not, which key is missing.
DNS propagation check
Whether a record change has reached the major public resolvers yet.
Domain registration lookup
Who a domain is registered through, when it expires, and whether it is locked against transfer.
IP allocation lookup
Who holds an IP address's network, which registry allocated it, and where to report abuse.
HTTP & TLS
SSL certificate check
Who issued a domain's certificate, when it expires, and how many days are left.
TLS version check
Which TLS versions a site still accepts — including the deprecated ones a browser hides from you.
HTTP security headers
Which security headers a site sends — HSTS, CSP, X-Frame-Options and the rest.
Redirect chain tracer
Every hop a URL takes before it lands, and the status code each one answered.
CAA records
Which certificate authorities are allowed to issue for a domain, and which name that rule comes from.
Built for our own fleet first.
They read public records
SPF, DMARC, DNS and certificate data are public by design. These tools read exactly what a mail server or a browser would read — nothing private, nothing stored, no account.
We run them on our own fleet
These are the checks we run against the domains and SaaS products we operate. That’s why a result explains what it means, instead of printing a record and leaving you to interpret it.
Configured is not the same as working
A record can be published and still do nothing: DMARC at p=none, an MTA-STS policy stuck in testing, a DNSSEC delegation whose keys don’t match. Most checkers report the record. These report what it does — and say plainly when they can’t tell.