Skip to content

Domain Health guide

Tool guide. Updated .

What the XGM Domain Health check covers, how its A to F grades are calculated, and how to work through findings for email, DNS, TLS, headers and redirects.

What Domain Health covers

A domain's health depends on several independent systems: the DNS delegation, the mail setup, the TLS certificate and the web server configuration. Problems in one area rarely show up in another, so checking only the website can miss an expired DMARC setup or a broken SPF record. Domain Health runs the core checks of five XGM tools together and summarises them.

Categories and what they check
CategoryChecksFull tool
Email authenticationSPF record and lookup count, DMARC policy and reports, MX recordsDMARC, SPF, MX
DNSName servers, website addresses (A/AAAA), duplicate SPF, misplaced DMARCDNS Lookup
TLS certificateCertificate validity, days remaining, negotiated TLS versionTLS Checker
HTTP security headersHSTS, CSP, X-Content-Type-Options, frame protection, Referrer-Policy, Permissions-PolicyHTTP Headers
RedirectsChain from http://, loops, downgrades, final statusRedirect Checker
How a Domain Health run proceedsDNS is checked first, then email and web checks run in parallel, each category is scored as it finishes, and the overall grade averages the completed categories.DNS lookupA, AAAA, MX, NS, TXT, CNAME for the domainEmail checksSPF with includes, DMARC at _dmarc, MX fromthe DNS resultWeb checks in parallelHTTPS request for TLS and headers; HTTPrequest for redirectsScore per category100 − 35 × critical − 12 × warning, floored at0Overall gradeAverage of completed categories, A to F
DNS is checked first, then email and web checks run in parallel, each category is scored as it finishes, and the overall grade averages the completed categories.

How to use Domain Health

  1. Open Domain Health and enter a registered domain, such as example.com.
  2. Wait 10 to 20 seconds while the checks run; categories fill in as they finish.
  3. Start with the overall grade and the count of critical findings, then open each category.
  4. Use Open tool next to a category for the full check, with raw data and more detailed findings.
  5. Export the result as JSON, Markdown, CSV or PDF, or create a snapshot link to compare later.
  6. Open the Full report tab for a scored server-side report: domain intelligence, website health (HTTP, robots.txt, sitemap and SEO basics) or DNS health, each with prioritised recommendations and a PDF.

Snapshots are useful before and after a change. Create one, make the fix, and open the snapshot link: the page runs a fresh check and lists which findings are new, resolved or changed in severity.

How grades are calculated

Each category starts at 100 points. Every critical finding costs 35 points and every warning costs 12; informational notes and passed checks cost nothing. The score never goes below zero, and the letter grade follows the score.

Score to grade
ScoreGradeTypical meaning
90–100ANo critical findings and no warnings
80–89BOne warning (88 points)
65–79COne critical finding (65) or two warnings (76)
50–64DThree or four warnings, or a critical finding plus a warning
0–49FTwo or more critical findings, or many warnings

The overall grade is the average of the categories that completed. If a check could not run, for example because the site has no HTTPS, that category shows an error instead of a score and does not count toward the average. The grade is a quick orientation, not a certification.

DKIM is not included

DKIM keys live under selector names that cannot be listed from DNS. To check DKIM, look at the Authentication-Results header of a real message with the Email Header Analyzer.

Working through the findings

Fix critical findings first, in the order that affects the most people. A broken SPF record or an expired certificate affects every message or every visitor, while a missing Permissions-Policy header is a refinement. The table suggests an order for the most common findings.

Suggested order
PriorityFindingWhere to read more
1Certificate expired or expiring within 14 daysSSL Checker guide
2SPF missing, multiple records or over 10 lookupsSPF lookup-limit guide
3No DMARC record, or DMARC records in the wrong placeDMARC guide
4Redirect loops, downgrades or chains ending in errorsRedirect guide
5TLS 1.0 or 1.1 negotiatedTLS 1.3 guide
6Missing HSTS or CSPHSTS guide, CSP guide
7DMARC at p=nonep=none to p=reject plan
Example: minimal records that clear the email category for a domain that sends through one provider
example.com.        IN MX  10 mail.example.net.
example.com.        IN TXT "v=spf1 include:_spf.mail.example.net -all"
_dmarc.example.com. IN TXT "v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@example.com"

Using it for regression checks

Most domain problems appear after a change: a DNS provider migration that dropped a TXT record, a new CDN that removed security headers, a certificate renewal that failed after a hosting move. Running Domain Health before and after every such change catches them while the change is still fresh in everyone's mind.

  • Create a snapshot link before the change and open it after the change to see what changed.
  • Add the check to your change checklist for DNS, hosting and mail migrations.
  • For scheduled monitoring, call the individual checks through the XGM API from a job.
  • Keep exports of results for audits, since they record exactly what was checked and when.

For agencies and teams managing many domains, the same routine scales: one run per domain after each change window, with exports kept per client.

Remember that results reflect public DNS and the public website as seen from the XGM server at that moment. Cached DNS answers, geo-dependent CDN behaviour or maintenance windows can make a result differ from what you see elsewhere.

FAQ

How long does a check take?

Usually 10 to 20 seconds. DNS and email checks are quick; the web checks wait for the site to respond and follow redirects.

Why is a category marked as not completed?

The check could not run, for example because HTTPS is not available or a DNS lookup timed out. The category does not count toward the overall grade.

Is an A grade a guarantee of security?

No. The grade reflects a set of public configuration checks. Application security, access control and monitoring are outside its scope.

Why is DKIM missing?

DKIM keys are published under selector names chosen by each sending service, and DNS cannot list them. Check DKIM from the headers of a real message instead.

Can I check a subdomain?

Yes, enter the full name. Email results then reflect the subdomain's own SPF and MX records and the DMARC policy that applies to it.

How do I compare two domains?

Export both results, or use the Compare feature in the individual tools, which lists findings side by side for two targets.

Why did my grade change without any change on my side?

Something outside your configuration changed: a certificate got closer to expiry, a provider added includes to its SPF record, or a CDN changed its headers. A snapshot link from an earlier run shows exactly which findings changed.

Is Domain Health enough for email deliverability?

It covers the DNS side of email: SPF, DMARC and MX. Deliverability also depends on DKIM, sending IP reputation, complaint rates and list quality, which the deliverability checklist guide covers.

Should every domain score A?

Aim for no critical findings on every domain. Some warnings are deliberate trade-offs, such as a softer DMARC policy during a rollout; document those instead of chasing a perfect grade.

Does XGM store the result?

No. Results stay in your browser unless you create a snapshot link, which stores the verdict and finding titles until the link expires.

Sources