← All Tools

Domain Security Review ドメイン診断

One domain in — DNS, email authentication, TLS, HTTP headers, CAA and HSTS checked in one pass by six of the site’s tools and scored together. Each finding links to the standalone tool with the domain pre-filled.

⚠ Server-assisted. The six checks query the domain from our server (DNS, port 443, one HTTPS request) — your IP is never forwarded, and the site’s per-tool rate limits apply. Only review domains you own or are authorised to assess. Findings stay in memory unless you tick “Keep this case in my browser”.
Which domain?

A bare domain (example.com). Subdomains work for TLS and headers; SPF / DMARC / CAA are looked up where the records actually live.

1 DNS records idle / 10 pts

Does the domain resolve, with redundant name servers and a mail exchanger? Open DNS Record Lookup →

Waiting for a run.

2 Email authentication idle / 30 pts

SPF, DKIM and DMARC — can this domain be spoofed? Open Email Security Checker →

Waiting for a run.

3 TLS certificate idle / 25 pts

Trusted chain, name match, expiry and key strength on port 443. Open SSL Checker →

Waiting for a run.

4 HTTP security headers idle / 25 pts

HSTS, CSP, X-Content-Type-Options, framing, Referrer-Policy, Permissions-Policy. Open HTTP Security Headers Grader →

Waiting for a run.

5 CAA & HSTS preload idle / 10 pts

Which CAs may issue for the domain, and is HSTS preload-eligible? Open CAA & HSTS Checker →

Waiting for a run.

6 Posture extras idle not scored

DNSSEC, MTA-STS and security.txt — informational, not scored. Open Domain Security Posture Scanner →

Waiting for a run.

Report & export

A Markdown report of every finding (paste into a ticket), plus the case artifacts — IPs, name servers, mail hosts, certificate names — as CSV or STIX 2.1.