Free tool
Free website and domain report
One report on your email security, DNS, SSL, security headers, cookies, registration and reputation, with a link you can share with your IT provider.
What you get out of it
- Every public check we run, grouped and counted: what passed, what to review, what to fix.
- A plain-English explanation and fix for each finding.
- A private link you can send to your web developer or IT provider.
A one-off check is a snapshot. Add the domain to DomainGuard and it is watched: its uptime every five minutes on every plan, and on Starter and up every check here again each day, with an alert in the app when something important changes. What DomainGuard watches
What it checks
Email Authentication
- SPF record checkSPF lists the servers allowed to send email as your domain. Without a valid one, your mail lands in spam and forgeries get through.
- SPF lookup limit checkAn SPF record may trigger at most 10 DNS lookups. Past that, receivers treat it as broken and your mail loses its SPF pass.
- SPF policy strength checkThe ending of your SPF record (-all, ~all, ?all or +all) decides what receivers do with mail from servers you did not list.
- DKIM record checkDKIM puts a tamper-proof signature on every email you send. Receivers use it to prove the message really came from you.
- DMARC record checkDMARC tells receivers what to do with email that fails SPF and DKIM, and sends you reports on who is sending as your domain.
- MX record checkMX records tell the internet which servers receive email for your domain. Wrong or missing MX means lost mail.
- MTA-STS checkMTA-STS tells other mail servers they must use encryption when delivering to you, closing off downgrade and interception attacks.
- TLS-RPT checkTLS-RPT asks other mail servers to report when they could not deliver to you securely, so you hear about problems before mail is lost.
- DNS lookup checkBefore we can check anything about your email, your domain's DNS has to answer. This check says when it did not.
DNS Health
SSL/TLS & Website
- Website reachability checkWhether your website answered at all. If this fails, most other website checks could not run.
- HTTPS connection checkWhether your site completes a secure HTTPS connection with a certificate browsers trust.
- SSL certificate checkThe certificate your website presents: who issued it, which names it covers, and when it expires.
- Certificate expiry checkAn expired SSL certificate turns your website into a browser warning. We check how many days yours has left.
- Certificate trust and chain checkWhether browsers trust the certificate: issued by a real authority, served with its full chain, and not revoked.
- Certificate name checkThe certificate has to name the exact hostname a visitor types. If it names something else, browsers refuse it.
- Certificate key and signature checkWhether your certificate uses a key and signature strong enough for today's browsers.
- TLS version checkWhether your server still accepts retired encryption (TLS 1.0 and 1.1) and whether it offers the current one (TLS 1.3).
- CAA record checkA CAA record names the certificate authorities allowed to issue certificates for your domain, and blocks the rest.
- HTTP to HTTPS redirect checkVisitors who type your address without https:// should be sent to the secure version automatically.
- HTTP status checkThe status code your homepage answers with. Anything but a success means visitors and search engines are not seeing your site.
- Response time checkHow long your server takes to answer. Over a second feels slow to visitors; over three loses them.
- Mixed content checkAn HTTPS page that loads images or scripts over plain HTTP. Browsers block them or mark the page as not fully secure.
- Parked domain checkWhether your domain is showing a registrar's parking page (ads, "this domain may be for sale") instead of your website.
- Cross-domain redirect checkYour domain sends visitors to a different domain. Fine if intended; worth knowing if not.
Security Headers
- HSTS checkHSTS tells browsers to only ever use HTTPS for your site, so a visitor on public Wi-Fi cannot be quietly downgraded.
- Content-Security-Policy checkCSP tells browsers which scripts your site is allowed to run, which stops most injected code from running on your visitors.
- X-Frame-Options checkStops other websites from loading yours inside an invisible frame to trick visitors into clicking things (clickjacking).
- X-Content-Type-Options checkStops browsers guessing a file's type, which blocks a class of attacks that disguise scripts as images or text.
- Referrer-Policy checkControls how much of your page addresses leak to other sites when visitors click a link.
- Permissions-Policy checkSwitches off browser features your site does not use (camera, microphone, location) so injected code cannot use them either.
- Cross-origin policy checkTwo headers that isolate your pages from other sites a visitor has open, closing off cross-site data leaks.
- X-XSS-Protection checkA retired header. Modern browsers ignore it, and the old filter it switched on could be abused, so it is best set to 0.
Page Security
- CSP script safety checkWhether your Content-Security-Policy still lets injected inline scripts and eval() run, which undoes most of what CSP is for.
- CSP violation reporting checkWhether your Content-Security-Policy tells you when it blocks something, so an attack or a broken page does not go unnoticed.
- Subresource integrity checkWhether scripts your site loads from other companies' servers carry a fingerprint, so a tampered copy is refused.
- Third-party script checkHow many other companies' scripts your homepage runs. Each one can see what your visitors see and type.
- Form security checkWhether the forms on your homepage send what people type over an encrypted connection.
- Cookie prefix checkWhether your site's important cookies use the __Host- and __Secure- name prefixes that make browsers enforce their protections.
Cookie Security
Domain Registration
- Domain expiration checkWhen your domain registration runs out. An expired domain takes your website and email down together.
- Domain age checkHow long ago the domain was registered. Very new domains are treated with more suspicion by spam filters.
- Registrar checkThe company your domain is registered with, and the account that controls everything else.
- Web host checkWhich company hosts your website, identified from the addresses your domain points to.
Technology
Other free checkers
- Email Security CheckerCheck SPF, DKIM, DMARC, MX, MTA-STS and TLS-RPT for your domain and find out whether your email can be spoofed or will land in spam.
- SPF CheckerCheck your domain's SPF record: whether it is valid, whether it stays under the 10-lookup limit, and how strictly it treats unlisted senders.
- DMARC CheckerCheck whether your domain has a DMARC record, what its policy is, and whether it protects your customers from email sent in your name.
- DKIM CheckerCheck whether your domain publishes DKIM keys for common mail providers, so receivers can verify your email is really from you.
- SSL CheckerCheck your website's SSL certificate: expiry date, trust chain, hostname coverage, TLS versions, HTTPS redirect and HSTS.
- Security Headers CheckerCheck your website's HTTP security headers (CSP, HSTS, X-Frame-Options and more) and cookie flags, with a fix for each one missing.
- DNS CheckerCheck your domain's nameservers, redundancy, MX records and CAA records, and find the DNS problems that take websites and email offline.
- Blacklist CheckerCheck whether the servers behind your domain are listed on the spam blocklists mail providers use to reject email.
- Domain Expiration CheckerCheck when your domain expires, who it is registered with, how old it is and who hosts the website, so a lapsed renewal never takes your site and email down.
