Check it right now, free and with no sign-up:
Before a visitor reaches your website or an email reaches you, the internet follows a chain: your registrar, your extension's registry, your name servers, then your zone. If one link gives way, everything after it gives way too. Here are the five families of points we check.
Is your domain paid up for a good while yet, and locked against a transfer you did not ask for? We also read which registrar it is registered with. This is the link that controls all the others.
They are what answers the whole world when someone looks for your website or your email. We check that there are at least two, on different networks, that they all answer, that they all say the same thing, and that none depends on a domain anyone could buy.
A name server should only answer what it is asked about your domains. We check that it refuses to hand the full list of your names to a stranger, that it does not relay for other domains, and that it does not announce its software version.
DNSSEC signs your DNS answers so they cannot be forged on the way. We check whether it is turned on, whether the chain of signatures holds, and whether the signature is declared at the registry.
The small settings that prevent bad surprises: who may issue a certificate for you (CAA), sensible timers, aliases that point to names that still exist, and no wildcard making any made-up subdomain answer.
The internet's directory. It translates your domain name into addresses computers understand, and says where to deliver the email meant for you. Every visit to your website starts with a question to DNS.
The registrar is the company you bought your domain from (GoDaddy, Namecheap, Web.com and so on). The registry runs a whole extension, like CIRA for .ca. The registrar records your choices at the registry, and the registry announces them to the world.
The server that holds your domain's record card and answers for it. Your DNS host usually gives you two to four. It is not necessarily the same company as your registrar.
All the records of your domain: the address of your website, your mail servers, your aliases. It is what your name servers publish.
A signature added to your DNS records. It lets whoever looks you up check that the answer really comes from you and was not changed on the way. For it to do anything, a fingerprint of your key has to be at the registry: that is the DS record.
The fingerprint of your DNSSEC key, published at your extension's registry through your registrar. It is the link that ties your signature to the rest of the internet. Without it, nobody checks your signatures.
A record naming the certificate authorities allowed to issue a certificate for your domain, for example Let's Encrypt. The others must refuse. It stops a certificate in your name from being issued behind your back.
A function meant to copy your whole zone to a backup server. Open to the public, it lets anyone download the full list of your names, including the ones you thought were discreet.
A name that points to another name, for example www pointing to a hosting service. If the service goes away and its name can be bought back, someone can publish their own content at your address.
No. It reads what your DNS already publishes, the way any computer looking for your website does. The only slightly unusual question is the zone transfer request: a well-configured server refuses it, and if it accepts, we keep only the number of records.
Because DNSSEC is not turned on. Without a signature, an attacker on the path can forge your DNS answers, however well the rest is set up. So the letter stays at B until DNSSEC is in place. Some serious defects cap lower: an open zone transfer at C, a name server anyone can buy at F.
That we could not check that point this time, often because a server answered too slowly. It is not a defect: a point not measured counts neither for nor against you. When a point not measured could change the letter, we would rather publish no grade than one that may be wrong.
Because DNS is managed at the level of the main domain: that is what has a registrar, name servers and a signature. Checking acme.com already checks the zone shop.acme.com depends on. The tool offers you the right name in one click.
No, and most small businesses do not have it yet. But it is the only protection against forged DNS answers, and with many hosts it takes a few clicks to turn on. That is why its absence is a point to watch, not an anomaly.
No. Email security (SPF, DKIM, DMARC) has its own free check and its own grade. The two complement each other: this one checks that your domain holds up, the other who can send email in its name.
No, and nobody can state that on your behalf. A well-kept DNS helps you maintain the external security measures Law 25 expects, and this page shows you where you stand on that specific point. CyberAzimut is not a certification body.
Two other free checks complete this one: Free email security check · Free typosquatting check