DOMAIN SECURITY DIAGNOSTICS

See what protects your domain, and what does not

Enter a domain to inspect publicly reachable configuration. No login, agent or installation is needed.

Check a domain

We inspect only publicly reachable configuration. No login, agent or installation is required.

No sign-upExternal checks onlyUsually under a minute
Non-invasiveNo exploitation or authenticated probing.
ActionableFindings ordered by real impact.
Evidence includedRaw technical detail remains available.

What DNS Tools checks

DNS Tools looks at a domain the way an outside party can: through public DNS, the mail servers named in its MX records, and its public website. Nothing is installed, and no account on your systems is used.

A full domain assessment groups its checks into six categories. Each check ends in a status that says what was verified, and each status is kept separate from how much the finding matters.

  • DNS security: record sets, delegation and DNSSEC, read from public resolvers.
  • Email authentication: SPF, DKIM and DMARC, including whether a policy is only monitoring or actually enforcing.
  • Mail transport: whether the MX hosts accept SMTP connections and offer encrypted transport.
  • Website security: HTTPS, certificate state and common browser-facing response headers.
  • Phishing exposure: lookalike domains of the name you enter, surfaced as candidates for you to review.
  • Reputation: blocklist lookups, only when a licensed provider has been enabled on the server.

Single-purpose tools as well

If you already know which control you are troubleshooting, forty individual tools cover it directly. They span DNS record lookups and propagation, email authentication and transport, network and port exposure, and web security headers and certificates.

Start with the Domain Assessment for a broad view, or open a tool such as the SPF checker, the DMARC checker or the MX lookup for one specific question.

How results are presented

Every check returns one of a small set of statuses: PASS, IMPROVE, RISK, UNKNOWN, NOT_APPLICABLE, INFORMATIONAL or, for optional sources that are not enabled, NOT CONFIGURED. Severity is a separate field and applies only to IMPROVE and RISK findings.

Coverage is reported on its own axis: how many of the planned checks reached a conclusion. A check that could not gather reliable evidence is shown as UNKNOWN and is never counted as a clean result. The overall posture is marked provisional when any check is unresolved.

Findings are ordered by impact rather than by protocol, and the raw technical evidence behind each one stays available. The guide on reading statuses explains each label precisely.

Reports by email

Results can be read on screen without signing in. A PDF diagnostic report is included, and a more detailed remediation report is available under the current offer. PDFs are delivered only to an email address you have verified; see Reports for what each contains.

Who it is for

The service is written for people who run or look after a domain and want an outside view of it, without needing to be a specialist.

  • Owners of small businesses who want a plain-language read on whether their domain identity is protected.
  • IT generalists and consultants who manage email and DNS for several organisations and need quick, evidence-backed checks.
  • Engineers who are fixing a specific problem, such as a failing SPF lookup or a missing STARTTLS offer, and want exact record data.
  • Anyone preparing a DNS change who wants a before-and-after comparison; the DNS change checklist pairs well with this.

What it does not do

DNS Tools is not an internal vulnerability scanner, does not log in to anything, does not attempt exploitation and does not match software versions to vulnerability databases. It reports on public configuration only, and it says so when evidence is missing rather than guessing.

Written by DNS Tools editorial · Last updated 2026-10-09