Back to home
Free check

Is your DNS well protected?

Check it right now, free and with no sign-up:

  1. Enter your domain
  2. CyberAzimut follows the chain that leads to it: registrar, registry, name servers, zone
  3. Get a grade from A to F on 23 checkpoints
  4. See what to fix first, in plain language

A well-kept DNS helps you maintain the external security measures Law 25 expects.

We keep the domain you enter and its grade for 13 months, with no IP address or identifier attached.

Learn more about DNS, DNSSEC and CAA

What this check looks at

Before a visitor reaches your website or an email reaches you, the internet follows a chain: your registrar, your extension's registry, your name servers, then your zone. If one link gives way, everything after it gives way too. Here are the five families of points we check.

Domain registration

Is your domain paid up for a good while yet, and locked against a transfer you did not ask for? We also read which registrar it is registered with. This is the link that controls all the others.

Name servers

They are what answers the whole world when someone looks for your website or your email. We check that there are at least two, on different networks, that they all answer, that they all say the same thing, and that none depends on a domain anyone could buy.

Server exposure

A name server should only answer what it is asked about your domains. We check that it refuses to hand the full list of your names to a stranger, that it does not relay for other domains, and that it does not announce its software version.

DNSSEC signing

DNSSEC signs your DNS answers so they cannot be forged on the way. We check whether it is turned on, whether the chain of signatures holds, and whether the signature is declared at the registry.

Zone hygiene

The small settings that prevent bad surprises: who may issue a certificate for you (CAA), sensible timers, aliases that point to names that still exist, and no wildcard making any made-up subdomain answer.

What this page does not do
  • It changes nothing. It asks your DNS the same questions any computer on the internet does, plus one zone transfer request of which it keeps only the number of records.
  • It does not keep the content of your zone. If your zone transfer is open, we count the records and throw them away.
  • It gives no provider-specific guide. The fixes shown are generic; the step-by-step for your registrar and your DNS host is reserved for the portal.
  • Some points cannot be measured by this free tool, such as whether your CAA matches your actual certificates. They show in grey, "not measured", and never count against you.
  • We keep the domain you enter and its grade for 13 months, with no IP address or identifier attached, to measure how the tool is used. There is no account to create, no card, and no address to hand over.
  • It is a snapshot. A change made a few minutes ago may not be visible everywhere yet.

DNS words, in plain language

DNSDomain Name System

The internet's directory. It translates your domain name into addresses computers understand, and says where to deliver the email meant for you. Every visit to your website starts with a question to DNS.

Registrar and registry

The registrar is the company you bought your domain from (GoDaddy, Namecheap, Web.com and so on). The registry runs a whole extension, like CIRA for .ca. The registrar records your choices at the registry, and the registry announces them to the world.

Name serverNS

The server that holds your domain's record card and answers for it. Your DNS host usually gives you two to four. It is not necessarily the same company as your registrar.

Zone

All the records of your domain: the address of your website, your mail servers, your aliases. It is what your name servers publish.

DNSSECDNS Security Extensions

A signature added to your DNS records. It lets whoever looks you up check that the answer really comes from you and was not changed on the way. For it to do anything, a fingerprint of your key has to be at the registry: that is the DS record.

DS recordDelegation Signer

The fingerprint of your DNSSEC key, published at your extension's registry through your registrar. It is the link that ties your signature to the rest of the internet. Without it, nobody checks your signatures.

CAACertification Authority Authorization

A record naming the certificate authorities allowed to issue a certificate for your domain, for example Let's Encrypt. The others must refuse. It stops a certificate in your name from being issued behind your back.

Zone transferAXFR

A function meant to copy your whole zone to a backup server. Open to the public, it lets anyone download the full list of your names, including the ones you thought were discreet.

AliasCNAME

A name that points to another name, for example www pointing to a hosting service. If the service goes away and its name can be bought back, someone can publish their own content at your address.

Common questions

Can the check break anything?

No. It reads what your DNS already publishes, the way any computer looking for your website does. The only slightly unusual question is the zone transfer request: a well-configured server refuses it, and if it accepts, we keep only the number of records.

Why is my grade capped at B when almost everything is green?

Because DNSSEC is not turned on. Without a signature, an attacker on the path can forge your DNS answers, however well the rest is set up. So the letter stays at B until DNSSEC is in place. Some serious defects cap lower: an open zone transfer at C, a name server anyone can buy at F.

What does "not measured" mean?

That we could not check that point this time, often because a server answered too slowly. It is not a defect: a point not measured counts neither for nor against you. When a point not measured could change the letter, we would rather publish no grade than one that may be wrong.

Why does the tool refuse my subdomain?

Because DNS is managed at the level of the main domain: that is what has a registrar, name servers and a signature. Checking acme.com already checks the zone shop.acme.com depends on. The tool offers you the right name in one click.

Is DNSSEC mandatory?

No, and most small businesses do not have it yet. But it is the only protection against forged DNS answers, and with many hosts it takes a few clicks to turn on. That is why its absence is a point to watch, not an anomaly.

Does my email count in this grade?

No. Email security (SPF, DKIM, DMARC) has its own free check and its own grade. The two complement each other: this one checks that your domain holds up, the other who can send email in its name.

Does this make me compliant with Québec's Law 25?

No, and nobody can state that on your behalf. A well-kept DNS helps you maintain the external security measures Law 25 expects, and this page shows you where you stand on that specific point. CyberAzimut is not a certification body.

Two other free checks complete this one: Free email security check · Free typosquatting check