Domain Health guide
What the XGM Domain Health check covers, how its A to F grades are calculated, and how to work through findings for email, DNS, TLS, headers and redirects.
What Domain Health covers
A domain's health depends on several independent systems: the DNS delegation, the mail setup, the TLS certificate and the web server configuration. Problems in one area rarely show up in another, so checking only the website can miss an expired DMARC setup or a broken SPF record. Domain Health runs the core checks of five XGM tools together and summarises them.
| Category | Checks | Full tool |
|---|---|---|
| Email authentication | SPF record and lookup count, DMARC policy and reports, MX records | DMARC, SPF, MX |
| DNS | Name servers, website addresses (A/AAAA), duplicate SPF, misplaced DMARC | DNS Lookup |
| TLS certificate | Certificate validity, days remaining, negotiated TLS version | TLS Checker |
| HTTP security headers | HSTS, CSP, X-Content-Type-Options, frame protection, Referrer-Policy, Permissions-Policy | HTTP Headers |
| Redirects | Chain from http://, loops, downgrades, final status | Redirect Checker |
How to use Domain Health
- Open Domain Health and enter a registered domain, such as
example.com. - Wait 10 to 20 seconds while the checks run; categories fill in as they finish.
- Start with the overall grade and the count of critical findings, then open each category.
- Use Open tool next to a category for the full check, with raw data and more detailed findings.
- Export the result as JSON, Markdown, CSV or PDF, or create a snapshot link to compare later.
- Open the Full report tab for a scored server-side report: domain intelligence, website health (HTTP, robots.txt, sitemap and SEO basics) or DNS health, each with prioritised recommendations and a PDF.
Snapshots are useful before and after a change. Create one, make the fix, and open the snapshot link: the page runs a fresh check and lists which findings are new, resolved or changed in severity.
How grades are calculated
Each category starts at 100 points. Every critical finding costs 35 points and every warning costs 12; informational notes and passed checks cost nothing. The score never goes below zero, and the letter grade follows the score.
| Score | Grade | Typical meaning |
|---|---|---|
| 90–100 | A | No critical findings and no warnings |
| 80–89 | B | One warning (88 points) |
| 65–79 | C | One critical finding (65) or two warnings (76) |
| 50–64 | D | Three or four warnings, or a critical finding plus a warning |
| 0–49 | F | Two or more critical findings, or many warnings |
The overall grade is the average of the categories that completed. If a check could not run, for example because the site has no HTTPS, that category shows an error instead of a score and does not count toward the average. The grade is a quick orientation, not a certification.
DKIM is not included
Authentication-Results header of a real message with the Email Header Analyzer.Working through the findings
Fix critical findings first, in the order that affects the most people. A broken SPF record or an expired certificate affects every message or every visitor, while a missing Permissions-Policy header is a refinement. The table suggests an order for the most common findings.
| Priority | Finding | Where to read more |
|---|---|---|
| 1 | Certificate expired or expiring within 14 days | SSL Checker guide |
| 2 | SPF missing, multiple records or over 10 lookups | SPF lookup-limit guide |
| 3 | No DMARC record, or DMARC records in the wrong place | DMARC guide |
| 4 | Redirect loops, downgrades or chains ending in errors | Redirect guide |
| 5 | TLS 1.0 or 1.1 negotiated | TLS 1.3 guide |
| 6 | Missing HSTS or CSP | HSTS guide, CSP guide |
| 7 | DMARC at p=none | p=none to p=reject plan |
example.com. IN MX 10 mail.example.net.
example.com. IN TXT "v=spf1 include:_spf.mail.example.net -all"
_dmarc.example.com. IN TXT "v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@example.com"Using it for regression checks
Most domain problems appear after a change: a DNS provider migration that dropped a TXT record, a new CDN that removed security headers, a certificate renewal that failed after a hosting move. Running Domain Health before and after every such change catches them while the change is still fresh in everyone's mind.
- Create a snapshot link before the change and open it after the change to see what changed.
- Add the check to your change checklist for DNS, hosting and mail migrations.
- For scheduled monitoring, call the individual checks through the XGM API from a job.
- Keep exports of results for audits, since they record exactly what was checked and when.
For agencies and teams managing many domains, the same routine scales: one run per domain after each change window, with exports kept per client.
Remember that results reflect public DNS and the public website as seen from the XGM server at that moment. Cached DNS answers, geo-dependent CDN behaviour or maintenance windows can make a result differ from what you see elsewhere.
FAQ
How long does a check take?
Usually 10 to 20 seconds. DNS and email checks are quick; the web checks wait for the site to respond and follow redirects.
Why is a category marked as not completed?
The check could not run, for example because HTTPS is not available or a DNS lookup timed out. The category does not count toward the overall grade.
Is an A grade a guarantee of security?
No. The grade reflects a set of public configuration checks. Application security, access control and monitoring are outside its scope.
Why is DKIM missing?
DKIM keys are published under selector names chosen by each sending service, and DNS cannot list them. Check DKIM from the headers of a real message instead.
Can I check a subdomain?
Yes, enter the full name. Email results then reflect the subdomain's own SPF and MX records and the DMARC policy that applies to it.
How do I compare two domains?
Export both results, or use the Compare feature in the individual tools, which lists findings side by side for two targets.
Why did my grade change without any change on my side?
Something outside your configuration changed: a certificate got closer to expiry, a provider added includes to its SPF record, or a CDN changed its headers. A snapshot link from an earlier run shows exactly which findings changed.
Is Domain Health enough for email deliverability?
It covers the DNS side of email: SPF, DMARC and MX. Deliverability also depends on DKIM, sending IP reputation, complaint rates and list quality, which the deliverability checklist guide covers.
Should every domain score A?
Aim for no critical findings on every domain. Some warnings are deliberate trade-offs, such as a softer DMARC policy during a rollout; document those instead of chasing a perfect grade.
Does XGM store the result?
No. Results stay in your browser unless you create a snapshot link, which stores the verdict and finding titles until the link expires.