DNS Records

Domain Health Report

Run every check at once — delegation, addresses, SPF, DMARC, CAA and DNSSEC — and get one graded report.

Domain name
Output

Result appears here after you select

{ } How to use

  1. Enter a domain name, without http:// or a path.
  2. Select Process. Each area is checked in turn — it takes a few seconds because it is a dozen real lookups.
  3. Read the grid, or download the report, which also lists what could not be checked.

{ } How it works

Domain Health Report works on the text you provide. Select Process ▸ and it runs entirely in your browser — nothing is uploaded to a server — then shows the result in the Output panel.

Input

  • Domain name — paste or type your input in the left panel (use Sample for an example)

Output

TXT text — copy or download it from the Output panel.

{ } Common uses

  • Check a domain you have just set up before it goes live.
  • Audit a domain you have inherited and know nothing about.
  • Show someone non-technical why their email is going to spam.
  • Confirm a change to SPF or DMARC actually took effect.

{ } Limitations

  • This is a DNS-and-email report. It cannot check the TLS certificate on the live site, its HTTP headers, or whether it is reachable at all — a browser is not allowed to see any of that for another origin. The report says so at the end rather than leaving the impression it looked.
  • The score weights every check equally. A domain with no IPv6 and no CAA is not in the same trouble as one with no SPF, so read the rows and not just the number.
  • Answers come from one resolver. A change made in the last few minutes may not have reached it — use DNS Propagation to compare.

{ } FAQ

Is my data uploaded to a server?

No. Everything runs locally in your browser — your files never leave your device.

Can I process more than one file at once?

This tool works on one input at a time.

Is this tool free?

Yes — it’s completely free and needs no sign-up.

Why is my score not 100 when nothing is wrong?

Because several checks are best practice rather than correctness. A domain with no IPv6 address, no CAA record and an unsigned zone works perfectly well and will still lose marks — those are things worth doing, not things that are broken. The detail column says which is which.

It says my SPF is fine but mail still fails. Why?

SPF only covers the envelope sender, and it breaks on forwarding. If DMARC is at p=none you are also not seeing the reports that would tell you which sender is failing. Set up DMARC reporting and read a week of it before changing anything else.

Is anything sent to a server?

Only the DNS queries themselves, to a public DNS-over-HTTPS resolver — the same ones your browser and operating system already use. There is no backend here, and nothing about you is sent anywhere.

Why does it not check my SSL certificate?

Because a browser cannot. There is no API that exposes the certificate of a connection to JavaScript, and a cross-origin response is opaque, so a certificate check would require a server to make the connection for you. Rather than pretend, the report lists it as not checked.