Free domain health checker
Nine checks on any domain's website and email set-up, a grade from A to F, and a plain-English fix for everything that needs one. No sign-up needed.
We don't keep a record of the domains you check. Results are reused for 10 minutes if the same domain is checked again.
What we check
- DMARCRecord exists and is valid, the policy (none, quarantine or reject), pct, and where reports go.
- SPFOne valid record, DNS lookups within the limit of 10, and no +all or ?all.
- DKIMYour selectors, or common ones we look for. Key present and long enough.
- HTTPS certificateApex and www: expiry (warns at 21 days, fails at 7), a valid chain and a matching hostname.
- Domain registrationExpiry date from RDAP, including .uk domains. Warns at 30 days, fails at 7.
- BlacklistsMail server addresses, and sending addresses seen in DMARC reports, against reputable blacklists.
- MTA-STS and TLS-RPTBoth records present, and the policy file served over valid HTTPS.
- Mail serversMX records resolve and the servers answer on port 25.
- DNS changesName servers, website, mail and TXT records compared with the day before, with every change logged.
Understand the results
- What is DMARC?What DMARC does, how it works with SPF and DKIM, what none, quarantine and reject mean, and how to move a client to reject safely.
- SPF and the 10-lookup limitHow SPF works, why records quietly break as clients add new services, and how to fix a record with too many DNS lookups.
- DKIM explainedHow DKIM signing works, how to find a domain's selectors, why 1024-bit keys get flagged, and how to change keys without a gap.
- MTA-STS and TLS-RPTHow MTA-STS makes sure email to a domain arrives encrypted, how TLS-RPT reports problems, and how to switch both on safely.