Type a domain and see how its email authentication, HTTPS certificate, security headers and DNS look from the outside, with a plain-English fix for each item.
SPF, DKIM, DMARC, the certificate and six headers, in about 20 seconds.
Domain & Email Health Check
northwind.example
Check
Email authentication
SPF · DKIM · DMARC · MTA-STS
HTTPS & certificate
certificate · TLS · redirect
Security headers
six response headers
DNS
A · NS · MX · CAA · DNSSEC
public DNS answersone TLS handshakeone homepage requestno port scanningno probing
The same answers anyone on the internet can see about the domain.
01Type a domainOnly public settings are read
Sample data · illustration
Transcript of the animation.
Type a domain (Only public settings are read). A visitor types northwind.example and presses Check. The tool runs four groups of passive checks: email authentication, HTTPS and the certificate, security headers, and DNS. It reads public DNS records and makes one request to the homepage.
DNS and mail servers (Where the domain points, who takes its mail). DNS comes first. The domain points at a web server, has two name servers, and two MX records with priorities 10 and 20, so it receives email. There is no CAA record, which is noted as a small warning.
SPF, DKIM and DMARC (Who may send as you, and what happens if not). SPF is one record ending in tilde all, and uses 6 of the 10 allowed DNS lookups, counted through every include. A DKIM key is found under the common selector s1. DMARC is published at p=none, which only monitors: failing mail is still delivered, so it is flagged as a warning.
Certificate and redirect (Is HTTPS valid, and is it the default?). One TLS connection reads the certificate: a trusted chain, valid for the domain, with 54 days left, over TLS 1.3. Then a request to http://northwind.example gets a permanent redirect to https, so visitors always end up on the encrypted site.
Security headers (Read from the homepage response). The homepage response is checked for six security headers. Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options and Referrer-Policy are present. Content-Security-Policy and Permissions-Policy are missing, so both are flagged.
Grade and fix list (What to change first). Weighted together, the sample scores 89 out of 100, grade B: it passes most of these public checks. The fix list starts with moving DMARC from p=none to quarantine, then adding a Content-Security-Policy, a Permissions-Policy and a CAA record. A Get help button leads to a conversation about fixing them.
A sample domain, drawn as an illustration. The domain, hosts and results are fictional.
Run the check
Check a domain
Results are not stored. Each domain's result is cached for ten minutes.
What we check and why
Four groups of public settings
SPF · DMARC · DKIM · MTA-STS · TLS-RPT · BIMI
Email authentication
SPF lists the servers allowed to send as you, DKIM signs each message, and DMARC tells receivers what to do when both fail and sends you reports. Without them, anyone can send mail that looks like yours, and your real mail is more likely to land in spam. SPF also has a hard limit of ten DNS lookups, which we count through every include.
certificate · expiry · TLS version · http to https
HTTPS & certificate
Browsers warn visitors away from a site with an expired, untrusted or mismatched certificate. We read the certificate from one TLS connection, count the days left, and check that plain http:// sends visitors to https://.
A few response headers tell the browser how strict to be: always use HTTPS, which scripts may run, whether other sites may frame your pages. They are read from the homepage response only. They help, but they do not make a site secure on their own.
A/AAAA · NS · MX · CAA · DNSSEC
DNS
Where the domain points, who answers for it, which servers take its email, which certificate authorities may issue for it, and whether its DNS answers are signed. DNSSEC is shown for information and does not change the grade.
Honest scope
What this is, and what it is not
It is
✓A passive check of public settings: DNS records anyone can look up, one TLS handshake and one request to your homepage.
✓A quick way to spot common gaps in email authentication, HTTPS and response headers.
✓Plain-English reasons and a fix for each item, a grade from documented weights, and a report you can copy or download.
It is not
–A penetration test or a security audit. It does not scan ports, crawl pages or probe for vulnerabilities.
–Proof that a site is secure. A good grade means it passes these public checks, nothing more.
–A full DKIM audit. Keys under custom selector names cannot be found from outside, so not found is not the same as missing.
Want these fixed?
We set up email authentication (SPF, DKIM and DMARC, step by step to an enforcing policy) and harden hosting: certificates, redirects and security headers.