Domain Health Checker
One check for DNS, email authentication, TLS, security headers and redirects, with a grade per area and a full report.
Related tools
- Email SecurityCheck SPF, DKIM, DMARC, MTA-STS, TLS-RPT and BIMI for a domain and get the records to fix them.
- DNS LookupLook up DNS records by type, including reverse (PTR) lookups for IP addresses.
- MX & SMTPCheck a domain's mail servers and test SMTP connections, STARTTLS and open relay.
- TLS CheckerInspect a site's TLS certificate, expiry, issuer and negotiated protocol, with a renewal calendar you can download and a full report.
About this tool
Domain Health runs five checks against one domain at once and grades each area on its own: DNS records, email authentication (SPF, DMARC and whether MX records exist), the TLS certificate, the HTTP security headers and the redirect chain. Each category starts at 100 and loses 35 points for every critical finding and 12 for every warning; informational notes cost nothing, and the overall grade is the average of the categories that finished. Everything it reads is published: the domain’s public DNS records, one HTTPS request and one HTTP request to the bare domain. It does not open SMTP connections to your mail servers, query blocklists, or check DKIM, which needs the selector names only you know. Every category links to the tool that shows the full detail behind the grade.
Every check runs against public DNS and the public website from the XGM server. Scores are a quick orientation: 35 points off per critical finding and 12 per warning in each category. The linked tools show the full detail.
How to use it
- Open the Domain Health tool.
- Enter the public domain, hostname or IP address you want to check.
- Run the check; XGM queries it from its server and lists the findings.
- Copy the output only after checking it looks correct.
- Use related XGM tools if you need a broader diagnostic view.
FAQ
How is the grade for each area calculated?
Each category starts at 100, loses 35 points per critical finding and 12 per warning, and stops at 0. Informational findings and passed checks change nothing. The letter follows the score: A from 90, B from 80, C from 65, D from 50, F below that, and the overall grade is the average of the categories that completed.
Why is DKIM missing from the email section?
DKIM keys are published at selector._domainkey under your domain (RFC 6376), and DNS offers no way to list the selectors a domain uses. The check would have to guess names, so it is left out here. Email Security asks for your selectors and checks the keys they point at.
The TLS category says the handshake failed, but the site opens in my browser. Why?
The certificate is fetched by connecting to port 443 of the exact name you entered, with verification against the public trust store. A certificate that covers only the www name, a missing intermediate, or a self-signed certificate fails here while a browser that visits the www version succeeds. The finding quotes the handshake error, and SSL Checker shows the chain in full.
Does the MX line mean my mail servers were tested?
No. The email section only reads the MX records and reports how many exist, because a domain with no MX is a delivery problem in itself. Connecting to the servers, reading the banner, testing STARTTLS and probing for an open relay is the MX & SMTP tool, linked from that finding.
What exactly does the redirect category request?
One GET to http:// plus the name you entered, following up to six hops to the URL that finally answers. It flags chains longer than two hops, loops, any hop that goes from https:// back to http://, and a final URL that is still plain HTTP. Other starting points, such as the www variant, are traced in Redirect Checker.
Read the full Domain Health Checker guide