Domain Security Checker
Get an overview of how well a domain is protected against spoofing and hijacking. The checker reads public DNS and two public URLs: SPF and DMARC policies against email spoofing, MTA-STS and TLS-RPT for encrypted mail delivery, BIMI, DNSSEC against forged DNS answers, CAA records that limit which certificate authorities may issue certificates, a security.txt file for vulnerability reports, and HTTPS with HSTS on the website.
- Encrypted connection
- No sign-up
- Free to use
How to use Domain Security Checker
- Enter a domain.
- Click Check domain security.
- Fix email authentication first.
- Add DNSSEC, CAA and security.txt.
Domain Security Checker features
Email authentication
SPF, DMARC, MTA-STS, TLS-RPT, BIMI.
DNS
DNSSEC and CAA.
Website
HTTPS, HSTS and security.txt.
Grade
Weighted towards anti-spoofing.
Public data only
Nothing sent to mail servers.
Links
Details in the dedicated checkers.
When to use Domain Security Checker
- Brand protection.
- Security questionnaires.
- Domain portfolio audits.
- IT onboarding checklists.
Domain Security Checker FAQ
Why does DMARC matter?
Without an enforcing DMARC policy anyone can send email that appears to come from your domain.
What is CAA?
A DNS record that lists which certificate authorities may issue certificates for your domain.
Do non-mail domains need SPF?
Yes – publish v=spf1 -all and a reject DMARC policy so the domain cannot be spoofed.
Why is DKIM not checked?
DKIM keys live under selectors that are not public; check them with the DKIM record checker.
Protect your name
Phishing that impersonates your domain harms your customers and reputation. SPF, DKIM and an enforcing DMARC policy are the most effective defence.
How it works: checks that need the network are made by our server through a guarded client that only connects to public addresses on the standard web ports, pins every connection to the validated address and limits time and response size. Pasted input is analysed in your browser and never sent. Nothing you check is stored, and requests are rate-limited to keep the service fair.
Every finding is rule-based and explained: the tool tells you what it saw, why it matters and what to change, instead of showing an unexplained score. Grades summarise the findings so you can compare sites and track progress after a fix, but the individual checks are what you should act on.
Only check systems you own or are authorised to assess. The probes behave like a normal browser or client – they read public responses and perform ordinary handshakes – and never try to exploit a weakness, guess passwords or overload a server.
Related tools on this site cover the rest of a security review – security header generators, CSP and CORS generators, SSL certificate and expiry checks, SPF, DKIM and DMARC record checkers, JWT tools and password generators – so you can fix what you find in the same place.
Who it is for: developers hardening a release, system administrators and DevOps teams, security and compliance reviewers preparing for audits such as PCI DSS or ISO 27001, and site owners who want to know whether their basics are right. No account or installation is needed.