See what protects your domain, and what does not
Enter a domain to inspect publicly reachable configuration. No login, agent or installation is needed.
Check a domain
We inspect only publicly reachable configuration. No login, agent or installation is required.
Popular tools
Parse a domain's SPF record, follow every include and redirect, and count DNS lookups and void lookups against the limits receivers enforce.
Walk the _dmarc tree for a domain, read its policy and tags, and check separately whether external report destinations are authorised.
Check MX records, priorities, null MX and whether each mail server name resolves to a public address. Understand how inbound mail is routed for a domain.
See which TLS versions a server accepts, the negotiated protocol and cipher, and the full certificate chain with names, validity, key and signature details.
Paste message headers to trace the Received chain and read Authentication-Results, DKIM, ARC and From alignment. Every result is labelled a claim.
Test a fixed list of 31 common TCP ports on a public host and learn which services are reachable from the internet, with safe guidance for restricting them.
Check DNSSEC for a domain: DNSKEY and DS presence, DS-to-key match, algorithms, signature validity window and what validating public resolvers return.
Check for a security.txt file at the standard location, validate its Contact and Expires fields, and see how to give researchers a safe way to report issues.
What DNS Tools checks
DNS Tools looks at a domain the way an outside party can: through public DNS, the mail servers named in its MX records, and its public website. Nothing is installed, and no account on your systems is used.
A full domain assessment groups its checks into six categories. Each check ends in a status that says what was verified, and each status is kept separate from how much the finding matters.
- DNS security: record sets, delegation and DNSSEC, read from public resolvers.
- Email authentication: SPF, DKIM and DMARC, including whether a policy is only monitoring or actually enforcing.
- Mail transport: whether the MX hosts accept SMTP connections and offer encrypted transport.
- Website security: HTTPS, certificate state and common browser-facing response headers.
- Phishing exposure: lookalike domains of the name you enter, surfaced as candidates for you to review.
- Reputation: blocklist lookups, only when a licensed provider has been enabled on the server.
Single-purpose tools as well
If you already know which control you are troubleshooting, forty individual tools cover it directly. They span DNS record lookups and propagation, email authentication and transport, network and port exposure, and web security headers and certificates.
Start with the Domain Assessment for a broad view, or open a tool such as the SPF checker, the DMARC checker or the MX lookup for one specific question.
How results are presented
Every check returns one of a small set of statuses: PASS, IMPROVE, RISK, UNKNOWN, NOT_APPLICABLE, INFORMATIONAL or, for optional sources that are not enabled, NOT CONFIGURED. Severity is a separate field and applies only to IMPROVE and RISK findings.
Coverage is reported on its own axis: how many of the planned checks reached a conclusion. A check that could not gather reliable evidence is shown as UNKNOWN and is never counted as a clean result. The overall posture is marked provisional when any check is unresolved.
Findings are ordered by impact rather than by protocol, and the raw technical evidence behind each one stays available. The guide on reading statuses explains each label precisely.
Reports by email
Results can be read on screen without signing in. A PDF diagnostic report is included, and a more detailed remediation report is available under the current offer. PDFs are delivered only to an email address you have verified; see Reports for what each contains.
Who it is for
The service is written for people who run or look after a domain and want an outside view of it, without needing to be a specialist.
- Owners of small businesses who want a plain-language read on whether their domain identity is protected.
- IT generalists and consultants who manage email and DNS for several organisations and need quick, evidence-backed checks.
- Engineers who are fixing a specific problem, such as a failing SPF lookup or a missing STARTTLS offer, and want exact record data.
- Anyone preparing a DNS change who wants a before-and-after comparison; the DNS change checklist pairs well with this.
What it does not do
DNS Tools is not an internal vulnerability scanner, does not log in to anything, does not attempt exploitation and does not match software versions to vulnerability databases. It reports on public configuration only, and it says so when evidence is missing rather than guessing.
Written by DNS Tools editorial · Last updated 2026-10-09
Building your security posture.
Layers are checked in parallel. Each shows how many of its checks have actually finished, and anything that fails or times out is reported as such.
What should you fix?
Ordered by security impact, not protocol.