Health report
A domain's full health report
All four checks at once: expiry, certificate, email authentication, reputation. This is the report you can attach to a proposal — or run on a prospect's domain before a first meeting.
What it is actually for
A domain in trouble gives no warning. The certificate expires on a Sunday. The domain lapses over the holidays. The IP lands on a blacklist after a password leak. These four checks cover the overwhelming majority of what goes wrong on a client's domain, and not one of them needs access to anything.
The use nobody expects
Run it on a prospect's domain before the meeting. Thirty seconds later you know whether their certificate expires in three weeks, whether their SPF lets the world write in their name, or whether their IP is flagged. That is a sales argument, not a technical demo.
The chain
Four causes, two visible symptoms
A full check is not four boxes ticked side by side. Four different things can break, and between them they produce only two symptoms — the site stops answering, or the mail stops arriving. Which is why you look at all four at once. Break one.
What can break
What you see
The site answers
Visitors get through.
The mail arrives
Your messages are delivered.
All four checks pass. The site answers and the mail arrives.
Two different causes produce the same symptom, so one check on its own is never enough to conclude anything.
What this report does
Four checks, one address.
Expiry, certificate, mail authentication, reputation — four different sources queried in one go, and four failures that never arrive together.
- 4checks in a single pass
- 1address to type
- 0account to create
Reading the report
Every section keeps its own verdict, and the overall verdict is the worst of the four, never an average. Nothing is moderately expired. One section in fault colors the whole report.
- All clear
- All four sections are green. Neither the domain nor the certificate expires this month, email authentication holds, and no blacklist flags the domain.
- Worth watching
- At least one section wants action in the coming weeks, without breaking anything today. A due date under thirty days, an SPF that lets too much through, a DMARC that watches without blocking.
- Problem
- At least one section is in fault right now. A date passed or under a week away, a certificate browsers refuse, missing authentication, a listing in force. Start here.
- Unknown
- One section could not conclude — registry unreachable, no HTTPS server, blacklists silent. Nothing is wrong with the domain, and the tool would rather say so than count it as a pass.
What the report does not tell you
An honest check says where it stops. Five limits worth knowing before you send a report to a client.
The report is a photograph, not surveillance
What causes it: all four checks hold for the moment you clicked, and no longer. A certificate expiring tomorrow, a listing landing tonight, a renewal failing next week — none of that shows up here.
What fixes it: run the check on a regular basis, or hand it to monitoring that reruns it several times a day and writes to you when something moves.
DKIM unknown does not mean DKIM absent
What causes it: a DKIM selector carries whatever name the sending provider chose. The tool tries twelve of the most common ones, and a selector named anything else slips past.
What fixes it: ask the email provider for the selector before you conclude anything in a client report.
No HTTPS does not always mean no certificate
What causes it: the check queries the domain, then its www form, on port 443. A site served on another port, behind an access restriction, or on a subdomain answers nothing.
What fixes it: read the host actually queried, which the result shows, before you announce that there is no certificate.
An unpublished expiry date is not an unknown date
What causes it: several European registries keep the due date private. The tool shows unknown, and that says nothing about the health of the domain.
What fixes it: read the date in the registrar's customer area, where it is always on record.
An all clear on blacklists depends on how many lists answered
What causes it: large lists cap queries. The verdict covers the lists that answered, and nothing else.
What fixes it: read the count of lists queried, shown beside the result. When none of them answers, the tool refuses to conclude.
The four checks in the report
They run together rather than one after another, so the whole report takes no longer than the slowest of the four.
| Section | What it reads | Where it reads it | What a fault causes |
|---|---|---|---|
| Expiry | Due date, registrar, name servers, domain statuses. | The registry for the extension, over RDAP. | The site, the email and the subdomains all stop on the date. |
| Certificate | End date, issuer, names covered, state of the chain. | An encrypted connection to the site, on the domain then on its www form. | A full-screen warning for every visitor, and API calls that stop dead. |
| Email authentication | Mail servers, SPF record, DMARC record, DKIM signature across twelve selectors. | The domain's DNS zone. | Anyone can write in your name, and your own mail lands in junk more easily. |
| Reputation | The domain and the addresses of its site and its mail, across seven public lists. | The blacklists themselves, queried over DNS. | Part of the mail never arrives, with no visible error when you send. |
The thresholds applied to dates
Two of the four sections turn on a due date, and the same thresholds apply to both — the domain and the certificate.
| Days left | Verdict | What it means |
|---|---|---|
| More than 30 | All clear | Nothing to do today. The date is still worth knowing. |
| 30 or fewer | Worth watching | The due date falls inside the month, so check that the renewal will actually happen. |
| 7 or fewer | Problem | Handle it today. Past the date, the outage is immediate and total. |
| Date passed | Problem | The effect is already running. The day count starts at the date. |
Common questions
What exactly does this report check?
Four things, in one request. The domain's expiry date and its status at the registry, the site's certificate, the domain's email authentication, and its reputation across seven public blacklists. Each section is broken down above, along with the source it queries.
Do I need an account to get the report?
No. The result appears straight away, with no sign-up and no email address to leave. The tools are capped at around twenty checks an hour per visitor — enough to work through a whole portfolio, not enough to build an automated service on.
Can I run the report on a domain that is not mine?
Yes. Everything the tool reads is public. The registry, the certificate the site presents, the DNS records and the blacklists all answer whoever asks. The tool needs no access to the domain being checked, and it changes nothing there.
How long does the full report take?
The four checks run in parallel, so the whole thing takes no longer than the slowest of them, and that is capped. Anything that has not answered in time comes back as unknown rather than taking down the entire report.
How long does the result stay valid?
It does not, and that is the thing to remember. The report is timestamped to the second for exactly that reason. A due date moves closer every day, a certificate renews or fails to, a blacklist listing can land overnight. This check holds for today.
Can I send this report to a client?
That is what it is for. The report reads without technical knowledge — one verdict per section, one sentence per finding, and the raw data folded away for whoever wants it. Run it on a prospect's domain before a meeting and it tells you in thirty seconds what is wrong on their side.
Where the answers come from
Four sources, never the same one
No two of these four checks read the same thing. Which is why a domain can be green everywhere but one place, and why one screen was never going to be enough.
The extension's registry
Queried overRDAPfor the expiry date, the registrar, the name servers and the statuses. This is the name's official source, and the only authority on how long it lives.An encrypted connection to the site
Opened on the domain, then on its www form, for the end date, the issuer, the names covered and the state of the chain. Two addresses, because a certificate issued for one does not cover the other.The domain's DNS zone
Read for the mail servers,SPF,DMARCand theDKIMsignature. This is where it gets decided whether a stranger can write in your name.The blocklists themselves
Queried over DNS, on the domain name and on the addresses of its site and its mail. They warn nobody. The mail simply stops arriving.
These four failures never happen on the same day. That is what makes them easy to miss.
Twenty checks, no sign-up
- When does this domain expire?
- Is this SSL certificate valid, and when does it expire?
- Are your SPF, DKIM and DMARC set up right?
- Is this domain or its mail server blacklisted?
- Which servers receive mail for this domain?
- Which nameservers answer for this domain?
- What do this domain's TXT records do?
- Where does this CNAME end up?