Contact
All free tools

Domain health check

Check your domain's protection, whether more than one server answers for it, and whether its registration could expire. Type your domain and read the result in plain words.

  • DNSSEC
  • Nameservers
  • Registry agrees
  • SOA
  • CAA
  • Registration

Check your domain

It reads your domain's public records and its registry entry from your browser. Nothing is sent to us unless you choose to send the report.

Domain health checkRuns in your browser

About this check

What it looks at, and what it cannot see

A first look at whether your domain can be hijacked, knocked offline or lost when its registration runs out.

What does each result mean?

Each line is one part of your domain's setup, marked OK, Weak, Missing or Can't see, with what to do when something needs fixing.

DNSSEC
Signs your domain's answers so they cannot be forged on the way. It works only when the zone is signed and the registry holds a matching DS record.
Nameservers
The servers listed as answering for your domain. OK means at least two are listed, so one failure need not take the domain offline. Whether each one answers, on a separate network as it should, is for your DNS host to confirm.
Registry agrees
The nameservers your registry points to should be the ones your own DNS lists. A mismatch often means an old server still answers for part of the internet.
SOA
The zone's own settings: its primary nameserver, its serial number and the timers that tell the other servers how often to refresh.
CAA
Names the certificate authorities allowed to issue certificates for your domain. Without it, any authority may.
Registration
Who your registrar is and when the domain expires. The check warns when that is less than 30 days away.

Why is a domain without DNSSEC marked weak?

Because nothing proves its answers are real. Without DNSSEC, a forged answer can send your visitors or your mail somewhere else, and resolvers cannot check it.

It needs two parts to work: your DNS host signs the zone, and your registrar publishes the matching DS record. The check says which of the two is missing.

What can it not see?

It sees only what is public. The expiry date comes from the registry's RDAP service, and not every registry offers one. None is listed for .za domains such as .co.za, so for those it shows Can't see, and the date is in your registrar's account.

It cannot see who can log in to your registrar or DNS host, or whether those accounts use two-step sign-in. When it cannot read something, it says Can't see rather than guess.

Is the domain sent to you?

No. The check runs in your browser and reads public DNS through Cloudflare's public resolver and the registry's record through rdap.org. It stores nothing and sends nothing to us. The page shows no ads.

If you want help, Send us this report puts the domain and the findings into our contact form. Nothing reaches us until you send that form.

Want these fixed?

Send us the report, or tell us what is wrong with your domain. We'll tell you plainly what it takes to fix, before any work starts.