Skip to content

Health report

A domain's full health report

All four checks at once: expiry, certificate, email authentication, reputation. This is the report you can attach to a proposal — or run on a prospect's domain before a first meeting.

No sign-up, no email required. You can paste a full address — we'll pull the domain out of it.

What it is actually for

A domain in trouble gives no warning. The certificate expires on a Sunday. The domain lapses over the holidays. The IP lands on a blacklist after a password leak. These four checks cover the overwhelming majority of what goes wrong on a client's domain, and not one of them needs access to anything.

The use nobody expects

Run it on a prospect's domain before the meeting. Thirty seconds later you know whether their certificate expires in three weeks, whether their SPF lets the world write in their name, or whether their IP is flagged. That is a sales argument, not a technical demo.

The chain

Four causes, two visible symptoms

A full check is not four boxes ticked side by side. Four different things can break, and between them they produce only two symptoms — the site stops answering, or the mail stops arriving. Which is why you look at all four at once. Break one.

What can break

What you see

The site answers

Visitors get through.

The mail arrives

Your messages are delivered.

All four checks pass. The site answers and the mail arrives.

Two different causes produce the same symptom, so one check on its own is never enough to conclude anything.

What this report does

Four checks, one address.

Expiry, certificate, mail authentication, reputation — four different sources queried in one go, and four failures that never arrive together.

  • 4checks in a single pass
  • 1address to type
  • 0account to create

Reading the report

Every section keeps its own verdict, and the overall verdict is the worst of the four, never an average. Nothing is moderately expired. One section in fault colors the whole report.

All clear
All four sections are green. Neither the domain nor the certificate expires this month, email authentication holds, and no blacklist flags the domain.
Worth watching
At least one section wants action in the coming weeks, without breaking anything today. A due date under thirty days, an SPF that lets too much through, a DMARC that watches without blocking.
Problem
At least one section is in fault right now. A date passed or under a week away, a certificate browsers refuse, missing authentication, a listing in force. Start here.
Unknown
One section could not conclude — registry unreachable, no HTTPS server, blacklists silent. Nothing is wrong with the domain, and the tool would rather say so than count it as a pass.

What the report does not tell you

An honest check says where it stops. Five limits worth knowing before you send a report to a client.

  1. The report is a photograph, not surveillance

    What causes it: all four checks hold for the moment you clicked, and no longer. A certificate expiring tomorrow, a listing landing tonight, a renewal failing next week — none of that shows up here.

    What fixes it: run the check on a regular basis, or hand it to monitoring that reruns it several times a day and writes to you when something moves.

  2. DKIM unknown does not mean DKIM absent

    What causes it: a DKIM selector carries whatever name the sending provider chose. The tool tries twelve of the most common ones, and a selector named anything else slips past.

    What fixes it: ask the email provider for the selector before you conclude anything in a client report.

  3. No HTTPS does not always mean no certificate

    What causes it: the check queries the domain, then its www form, on port 443. A site served on another port, behind an access restriction, or on a subdomain answers nothing.

    What fixes it: read the host actually queried, which the result shows, before you announce that there is no certificate.

  4. An unpublished expiry date is not an unknown date

    What causes it: several European registries keep the due date private. The tool shows unknown, and that says nothing about the health of the domain.

    What fixes it: read the date in the registrar's customer area, where it is always on record.

  5. An all clear on blacklists depends on how many lists answered

    What causes it: large lists cap queries. The verdict covers the lists that answered, and nothing else.

    What fixes it: read the count of lists queried, shown beside the result. When none of them answers, the tool refuses to conclude.

The four checks in the report

They run together rather than one after another, so the whole report takes no longer than the slowest of the four.

SectionWhat it readsWhere it reads itWhat a fault causes
ExpiryDue date, registrar, name servers, domain statuses.The registry for the extension, over RDAP.The site, the email and the subdomains all stop on the date.
CertificateEnd date, issuer, names covered, state of the chain.An encrypted connection to the site, on the domain then on its www form.A full-screen warning for every visitor, and API calls that stop dead.
Email authenticationMail servers, SPF record, DMARC record, DKIM signature across twelve selectors.The domain's DNS zone.Anyone can write in your name, and your own mail lands in junk more easily.
ReputationThe domain and the addresses of its site and its mail, across seven public lists.The blacklists themselves, queried over DNS.Part of the mail never arrives, with no visible error when you send.

The thresholds applied to dates

Two of the four sections turn on a due date, and the same thresholds apply to both — the domain and the certificate.

Days leftVerdictWhat it means
More than 30All clearNothing to do today. The date is still worth knowing.
30 or fewerWorth watchingThe due date falls inside the month, so check that the renewal will actually happen.
7 or fewerProblemHandle it today. Past the date, the outage is immediate and total.
Date passedProblemThe effect is already running. The day count starts at the date.

Common questions

What exactly does this report check?

Four things, in one request. The domain's expiry date and its status at the registry, the site's certificate, the domain's email authentication, and its reputation across seven public blacklists. Each section is broken down above, along with the source it queries.

Do I need an account to get the report?

No. The result appears straight away, with no sign-up and no email address to leave. The tools are capped at around twenty checks an hour per visitor — enough to work through a whole portfolio, not enough to build an automated service on.

Can I run the report on a domain that is not mine?

Yes. Everything the tool reads is public. The registry, the certificate the site presents, the DNS records and the blacklists all answer whoever asks. The tool needs no access to the domain being checked, and it changes nothing there.

How long does the full report take?

The four checks run in parallel, so the whole thing takes no longer than the slowest of them, and that is capped. Anything that has not answered in time comes back as unknown rather than taking down the entire report.

How long does the result stay valid?

It does not, and that is the thing to remember. The report is timestamped to the second for exactly that reason. A due date moves closer every day, a certificate renews or fails to, a blacklist listing can land overnight. This check holds for today.

Can I send this report to a client?

That is what it is for. The report reads without technical knowledge — one verdict per section, one sentence per finding, and the raw data folded away for whoever wants it. Run it on a prospect's domain before a meeting and it tells you in thirty seconds what is wrong on their side.

Where the answers come from

Four sources, never the same one

No two of these four checks read the same thing. Which is why a domain can be green everywhere but one place, and why one screen was never going to be enough.

  1. The extension's registry

    Queried over RDAP for the expiry date, the registrar, the name servers and the statuses. This is the name's official source, and the only authority on how long it lives.
  2. An encrypted connection to the site

    Opened on the domain, then on its www form, for the end date, the issuer, the names covered and the state of the chain. Two addresses, because a certificate issued for one does not cover the other.
  3. The domain's DNS zone

    Read for the mail servers, SPF, DMARC and the DKIM signature. This is where it gets decided whether a stranger can write in your name.
  4. The blocklists themselves

    Queried over DNS, on the domain name and on the addresses of its site and its mail. They warn nobody. The mail simply stops arriving.
These four failures never happen on the same day. That is what makes them easy to miss.
An expiring certificate takes the site down within the hour. An expiring domain takes everything down, mail included. A listing takes nothing down and makes messages vanish in silence. A one-off report shows you all three. Only monitoring catches them first.